CVE-2026-93352

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file that passes all validation in MediaUploader::verifyExtension() and File::sanitizeFileName() because pht is not present in the blocklist, causing the file to be written to disk and executed as PHP when requested, enabling remote code execution with the privileges of the web server process.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 2 mentions on most recent observed day (2026-09-24)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-09-23: 1Mentions · 2026-09-24: 209-2309-24
Referenced assets3 URLs
Full discourse3 posts
  • Security Arsenal, LLC@SecurityAr58409

    🔒 #CyberSecurity CVE-2026-93352: Laravel-Mediable .pht Upload Bypass Enables PHP RCE on Apache —… "The NVD has published CVE-2026-93352, a CVSS 9.8 CRITICAL vulnerability affecting…" 🔗 https://securityarsenal.com/blog/cve-2026-93352-laravel-mediable-pht-upload-bypass-enables-php-rce-on-apache-detection-and-remediation-guide #CyberSecurity #ThreatIntel #cve202693352 #critical #cve

    0000027
    34 followersView on X
  • CVE@CVEnew

    CVE-2026-93352 Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in c… https://www.cve.org/CVERecord?id=CVE-2026-93352

    00000677
    58.1K followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🔴 Laravel-Mediable'da CVE-2026-93352 olarak takip edilen kritik RCE açığı keşfedildi. 7.0.0–7.0.1 sürümlerini etkileyen açık, .pht uzantısının dosya yükleme engel listesinde unutulması nedeniyle ortaya çıkıyor. Debian/Ubuntu üzerinde Apache'nin .pht dosyalarını PHP olarak çalıştırabilmesi, uzaktan kod çalıştırmaya yol açabiliyor. CVSS 3.1: 9.8 (Critical) Çözüm: 7.0.2 ve üzerine güncellemek. Patch commit: https://github.com/plank/laravel-mediable/commit/8ddb0e5b300084e91ad2cb18a6e7bc768bb7b008

    00000154
    2.4K followersView on X

Explore more