CVE-2026-4809Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign image MIME type, resulting in arbitrary file upload.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-26: 4Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 303-26
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4809 - Critical plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file uplo... https://www.thehackerwire.com/vulnerability/CVE-2026-4809/ https://t.co/ip1dNcuOmr

    Post summary

    A critical vulnerability (CVE-2026-4809) was disclosed for plank/laravel-mediable v6.4.0. It allows uploading dangerous file types when the application accepts or prefers client‑supplied MIME types, with details posted on The Hacker Wire.

    0000055
    163 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4809 plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME t… https://www.cve.org/CVERecord?id=CVE-2026-4809

    Post summary

    The tweet notes that CVE-2026-4809 in plank/laravel-mediable allows upload of dangerous file types, but provides no additional details, PoC, or evidence of exploitation.

    0000062
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4809: CRITICAL] Warning: Vulnerability in plank/laravel-mediable up to v6.4.0 allows malicious file uploads by manipulating MIME types. No patch available yet from the vendor. #CyberSecurity#cve,CVE-2026-4809,#cybersecurity https://cvefind.com/CVE-2026-4809

    Post summary

    A new critical vulnerability, CVE-2026-4809, in plank/laravel-mediable enables malicious file uploads via MIME type manipulation, with no patch yet released by the vendor.

    0000048
    606 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4809: Unsafe Cl... MIME type spoofing bypass lets attackers drop PHP shells as "images" - vendor ghosted disclosure, no patch incoming. #CVE20264809 #RCE #Laravel. https://zerodaysignal.com/vulnerability/CVE-2026-4809 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑4809 is a MIME type spoofing flaw in Laravel that permits attackers to drop PHP shells disguised as images. The vendor has not released a patch, and no exploit or active exploitation evidence is noted.

    0000059
    169 followersView on X

Explore more