CVE-2026-53691Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST "/admin/index.php?module=pages&mode=FileAdd" endpoint. The application fails to validate file extensions and MIME types, permitting the upload of arbitrary PHP scripts to the publicly accessible "/uploads/files/" directory where they can be executed directly by the web server.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-30: 3Technical Details · 2026-06-30: 306-30
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Authenticated Unrestricted File Upload to RCE in Redeight CMS (CVE-2026-53691) Redeight CMS 1.0 is vulnerable to unrestricted file upload in the admin pages module, specifically the /admin/index.php?module=pages&mode=FileAdd endpoint. The root cause is improper input validation, failing to enforce safe file extensions and MIME type checks during upload handling. An authenticated attacker can exploit this by sending a crafted POST request to upload an arbitrary PHP script, which is then reachable and runnable due to storage in the publicly accessible /uploads/files/ directory. Successful exploitation results in remote code execution on the server, enabling full site compromise, data theft, and potential lateral movement. 👉 Affected: Redeight CMS 1.0 | Upgrade to No fix yet — treat as suspicious

    Post summary

    A new CVE‑2026‑53691 in Redeight CMS 1.0 allows authenticated attackers to upload arbitrary PHP scripts via the /admin/index.php?module=pages&mode=FileAdd endpoint, resulting in remote code execution. No patch is currently available.

    0000075
    232 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-53691 An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST "/admin/index.php?m… https://www.cve.org/CVERecord?id=CVE-2026-53691 ----- Traducción: CVE-2026-53691 Una… http://infoflow.cloud`

    Post summary

    An unrestricted file upload vulnerability in Redeight CMS 1.0 allows authenticated attackers to execute arbitrary code via a POST request to /admin/index.php, as documented in CVE-2026-53691.

    0000033
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-53691 An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST "/admin/index.php?m… https://www.cve.org/CVERecord?id=CVE-2026-53691

    Post summary

    The passage announces CVE‑2026‑53691, highlighting an unrestricted file‑upload flaw that permits authenticated attackers to achieve remote code execution in Redeight CMS 1.0; it lacks exploit code, patch info, or evidence of active exploitation.

    00000843
    57.7K followersView on X

Explore more