CVE-2026-56124Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result set in an inline script block, exposing uploader IP addresses, Argon2ID key hashes, internal filenames, and SHA-256 fingerprints.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-359CWE-497

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-06-29); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-06-29: 4Mentions · 2026-06-30: 1Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-29: 3Technical Details · 2026-06-30: 106-2906-30
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-294
Disclosure2General1Patch1
2026-06-301
Patch1
Full discourse5 posts
  • しもしゃん@shimosyan
    General

    もらったCVE、2件目!!!!!!!! ‐ CVE-2022-24435 - [New] CVE-2026-56124

    Post summary

    The post simply lists two CVE identifiers without providing any further context or details.

    03090855
    2.8K followersView on X
  • しもしゃん@shimosyan
    Patch

    phpUploader v2.0.2を公開しました。 今回の更新で認証なしでのデータベース全体の情報漏洩に関する脆弱性(CVE-2026-56124)が対応されています。 v2.0.1 以前のすべてのバージョンが影響を受けます。ご利用されてる方はアップデートをお願いいたします。 https://github.com/shimosyan/phpUploader/releases/tag/v2.0.2

    Post summary

    The post announces the release of phpUploader v2.0.2, which contains a hot‑fix for CVE-2026-56124, an unauthenticated database disclosure vulnerability, and urges users to update.

    01050817
    2.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-56124 phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-fil… https://www.cve.org/CVERecord?id=CVE-2026-56124

    Post summary

    The text announces a CVE for phpUploader (pre‑2.0.2) that permits unauthenticated attackers to read the full contents of uploaded files.

    01000628
    57.7K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-56124 (CVSS 7.5) - phpUploader <2.0.2 exposes unauthenticated info disclosure. Attackers can access uploaded-files database including IP addresses, Argon2ID hashes, filenames & SHA-256 fingerprints. Patch immediately. #CVE #Vulnerability https://t.co/u0Xn1T1uLg

    Post summary

    The tweet announces a high‑severity information‑disclosure vulnerability in phpUploader and urges users to patch immediately.

    0000059
    55 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-56124 phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-fil… https://www.cve.org/CVERecord?id=CVE-2026-56124 ----- Traducción: CVE-2026-56124 php… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑56124, an unauthenticated information‑disclosure flaw in phpUploader before 2.0.2, and links to the CVE record without detailing any PoC, exploit tools, or patches.

    0000034
    89 followersView on X

Explore more