
🚨 HIGH - Authenticated Unrestricted File Upload to RCE in Redeight CMS (CVE-2026-53691) Redeight CMS 1.0 is vulnerable to unrestricted file upload in the admin pages module, specifically the /admin/index.php?module=pages&mode=FileAdd endpoint. The root cause is improper input validation, failing to enforce safe file extensions and MIME type checks during upload handling. An authenticated attacker can exploit this by sending a crafted POST request to upload an arbitrary PHP script, which is then reachable and runnable due to storage in the publicly accessible /uploads/files/ directory. Successful exploitation results in remote code execution on the server, enabling full site compromise, data theft, and potential lateral movement. 👉 Affected: Redeight CMS 1.0 | Upgrade to No fix yet — treat as suspicious
Post summary
A new CVE‑2026‑53691 in Redeight CMS 1.0 allows authenticated attackers to upload arbitrary PHP scripts via the /admin/index.php?module=pages&mode=FileAdd endpoint, resulting in remote code execution. No patch is currently available.


