CVE-2026-34415Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern. Unauthenticated attackers can exploit this flaw combined with authentication bypass and path traversal vulnerabilities to upload malicious PHP code, rename it with a .php4 extension, and execute arbitrary operating system commands on the server.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-22); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-22: 2Mentions · 2026-04-23: 2Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-22: 2Technical Details · 2026-04-23: 204-2204-23
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-222
Disclosure1Patch1
2026-04-232
Disclosure2
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34415 Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-execut… https://www.cve.org/CVERecord?id=CVE-2026-34415

    Post summary

    This entry announces CVE‑2026‑34415, highlighting incomplete input validation in Xerte Online Toolkit’s elFinder connector that could allow PHP execution in versions 3.15 and earlier.

    00001113
    57.2K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-34415 — CVSS 9.8/10 ██████████ Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/NmM53DiuHJ

    Post summary

    The tweet alerts on a critical CVE-2026-34415 affecting Xerte Online Toolkits, highlights its severity and the availability of a patch, but does not mention PoC, exploits, or active attacks.

    1000056
    28 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34415 Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-execut… https://www.cve.org/CVERecord?id=CVE-2026-34415 ----- Traducción: CVE-2026-34415 Xer… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-34415, describing an incomplete input validation flaw in Xerte Online Toolkit's elFinder connector that permits PHP execution. No exploit, patch, or active exploitation details are provided.

    0000034
    72 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34415: Xerte Online Toolkits File Uploa... Triple-threat RCE chain: auth bypass + path traversal + .php4 extension slip through regex - complete server takeover f... https://zerodaysignal.com/vulnerability/CVE-2026-34415 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-34415, detailing a triple‑threat RCE chain in Xerte Online Toolkit that allows authentication bypass, path traversal, and PHP4 extension exploitation for complete server takeover.

    0000098
    218 followersView on X

Explore more