Remote Code Execution in HortusFox ThemeModule
HortusFox versions prior to 6.2 are vulnerable to remote code execution via an insufficient validation flaw in the theme import process allowing arbitrary file uploads to the web root.
CVE search metadata
CVE search record: CVE-2026-104069. Severity: high. CVSS: 7.2. KEV: no. Product: HortusFox (< 6.2). Brief: Remote Code Execution in HortusFox ThemeModule. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-104069/
HortusFox versions prior to 6.2 are affected by a remote code execution vulnerability located within the ThemeModule::startImport() function. The vulnerability stems from an insecure file handling implementation where uploaded ZIP archives are extracted directly into the application's public web root. Critically, the system performs no validation on the file names, extensions, or content of the extracted files prior to placement in an executable directory. An authenticated administrator can leverage this by uploading a specially crafted theme archive containing both a malicious PHP script and an .htaccess file, which bypasses typical execution restrictions. By subsequently requesting the uploaded file via the themes directory, an attacker can execute arbitrary OS commands under the privileges of the web-server user.
Attack Chain
- Authenticated attacker logs into the HortusFox administrative interface.
- Attacker prepares a ZIP archive containing a PHP web shell and a custom .htaccess configuration file.
- Attacker navigates to the theme import feature and uploads the crafted ZIP archive.
- The application processes the upload through the vulnerable ThemeModule::startImport() function.
- The application extracts the contents of the ZIP archive directly into the public web root directory without validation.
- The .htaccess file is applied by the web server, enabling PHP execution for the attacker's script if previously restricted.
- Attacker requests the path to the uploaded PHP shell via a standard HTTP GET request.
- Web server executes the PHP script, providing the attacker with remote command execution capabilities.
Impact
Successful exploitation of this vulnerability allows an authenticated administrator to achieve full remote code execution on the underlying server. This results in complete compromise of the web application, potential lateral movement within the network, and access to sensitive data stored on or accessible to the web server process. The scope is limited to HortusFox instances running version 6.1 or earlier.
Recommendation
- Upgrade all HortusFox installations to version 6.2 or later immediately to patch the vulnerable ThemeModule::startImport() function.
- Implement strict file system permissions on the public web root to prevent the web server process from writing new executable files in directories where they are not required.
- Deploy file integrity monitoring on the /themes directory to alert on the creation of unexpected .php or .htaccess files.
- Enable and monitor web server access logs for requests to non-standard or unexpected files within the /themes directory structure.
Immediate actions
Upgrade HortusFox to 6.2 or later
Mitigations
Restrict web server write permissions to the themes directory
CVE-2026-104069
Detection coverage 1
Detect Suspicious File Creation in HortusFox Themes Directory
highDetects the creation of .php or .htaccess files within the HortusFox themes directory, which is a primary indicator of CVE-2026-104069 exploitation
Detection queries are available on the platform. Get full rules →