CVE-2026-2560Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of the component Media File Preview Plugin. Such manipulation of the argument localFile leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-16); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-16: 1Mentions · 2026-02-19: 1Technical Details · 2026-02-19: 102-1602-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Cybersecurity Aide@SecAideInfo
    Disclosure

    🚨#CyberAlert: CVE-2026-2560 found in #kalcaddle #kodbox v1.64.05! Vulnerability in Media File Preview Plugin allows OS command injection via `run` in VideoResize.class.php. 🛡️ Exploit public; vendor unresponsive. Act now to secure your systems! 🔒🔍 #Infosec #patchit

    Post summary

    CVE-2026-2560, an OS command injection flaw in kalcaddle kodbox’s Media File Preview Plugin, has a publicly available exploit and no vendor patch announced.

    0000032
    20 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2560 A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of th… https://www.cve.org/CVERecord?id=CVE-2026-2560

    Post summary

    The post announces CVE-2026-2560 in kalcaddle kodbox, pinpointing the affected function but offering no further technical or exploitation details.

    00000408
    56.4K followersView on X

Explore more