CVE-2026-34413Disclosure

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unauthenticated callers does not call exit() or die(), allowing PHP execution to continue and process the full request server-side. Unauthenticated attackers can perform file operations on project media directories including creating directories, uploading files, renaming files, duplicating files, overwriting files, and deleting files, which can be chained with path traversal and extension blocklist vulnerabilities to achieve remote code execution and arbitrary file read.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-497

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-23); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-23: 2Mentions · 2026-06-24: 1PoC Mentioned / Linked · 2026-06-24: 1Technical Details · 2026-04-23: 2Technical Details · 2026-06-24: 104-2306-24
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-232
Disclosure2
2026-06-241
Disclosure1
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-34413 - critical 🚨 Xerte Online Toolkits <= 3.15 - Remote Code Execution > Xerte Online Toolkits versions 3.15 and earlier expose the elFinder file manager conn... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-34413 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces the critical CVE‑2026‑34413 impacting Xerte Online Toolkits versions 3.15 and earlier, highlighting a RCE via elFinder and linking to further information.

    00012272
    959 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34413 Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.ph… https://www.cve.org/CVERecord?id=CVE-2026-34413 ----- Traducción: CVE-2026-34413 Xer… http://infoflow.cloud`

    Post summary

    The post announces the CVE-2026-34413 missing‑authentication flaw affecting Xerte Online Toolkits 3.15 and earlier, detailing the vulnerable elFinder connector endpoint.

    0000035
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34413 Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.ph… https://www.cve.org/CVERecord?id=CVE-2026-34413

    Post summary

    The post announces a missing authentication vulnerability in Xerte Online Toolkits 3.15 and earlier, specifically affecting the elFinder connector endpoint, and links to the CVE record for more details.

    00000106
    57.2K followersView on X

Explore more