Arbitrary File Upload Vulnerability in NivoCart File Manager
NivoCart versions 2.4.0 and earlier are vulnerable to remote code execution via an arbitrary file upload flaw in the File Manager multi() endpoint.
CVE search metadata
CVE search record: CVE-2026-94104. Severity: high. CVSS: 8.8. KEV: no. Product: NivoCart (<= 2.4.0). Brief: Arbitrary File Upload Vulnerability in NivoCart File Manager. Brief link: https://feed.craftedsignal.io/briefs/2026-09-nivocart-rce/
What's new
- 1. added coverage for NivoCart (<= 2.4.0) Sep 20, 12:21 via nvd
NivoCart versions 2.4.0 and earlier contain a critical arbitrary file upload vulnerability within the File Manager multi() endpoint. The application fails to validate file extensions during the upload process, particularly when the chunks parameter is set to 2 or higher. This security defect allows an attacker, even one with limited view-only back-office privileges, to bypass intended restrictions and upload malicious PHP scripts to the web-accessible image/data/ directory. Once the file is uploaded, the attacker can execute the script by directly navigating to the file path through a web browser, resulting in full remote code execution on the underlying server. This vulnerability presents a significant risk to NivoCart installations as it grants attackers the ability to compromise server-side operations and data.
Attack Chain
- Attacker gains unauthorized or low-privileged access to the NivoCart back-office panel.
- Attacker navigates to the File Manager component.
- Attacker initiates an upload request to the multi() endpoint.
- Attacker manipulates the request to set the chunks parameter to a value of 2 or higher.
- Attacker uploads a malicious PHP file, bypassing extension validation checks.
- The application saves the malicious file into the web-accessible image/data/ directory.
- Attacker requests the uploaded file directly via a web browser to execute the payload.
- Web server processes the PHP code, granting the attacker remote code execution.
Impact
Successful exploitation of this vulnerability allows an unauthenticated or low-privileged attacker to achieve remote code execution on the target server. This could lead to a full system compromise, data theft, unauthorized modification of site content, and potential lateral movement within the network. All NivoCart installations at or below version 2.4.0 are affected.
Recommendation
- Immediately restrict access to the NivoCart back-office panel to authorized personnel only to mitigate the impact of the required low-level access.
- Monitor web server access logs for anomalous POST requests to the File Manager multi() endpoint, specifically tracking requests containing the chunks parameter.
- Implement egress filtering on the web server to prevent post-exploitation activity such as reverse shells or data exfiltration.
- Periodically audit the image/data/ directory for unauthorized script files (e.g., .php files) that should not be present in an image storage folder.
- Upgrade NivoCart to a version beyond 2.4.0 once the vendor provides a patch to address the underlying validation flaw in the File Manager.
Immediate actions
Review access logs for POST requests to File Manager endpoints
Mitigations
Restrict back-office access via IP allowlisting or VPN
CVE-2026-94104
Detection coverage 1
Detect CVE-2026-94104 Exploitation - Arbitrary File Upload in NivoCart
highDetects exploitation of CVE-2026-94104 by monitoring for POST requests to the File Manager multi() endpoint with a chunks parameter greater than 1.
Detection queries are available on the platform. Get full rules →