Skip to content
Threat Feed
high advisory

Remote Code Execution in HortusFox ThemeModule

HortusFox versions prior to 6.2 are vulnerable to remote code execution via an insufficient validation flaw in the theme import process allowing arbitrary file uploads to the web root.

CVE search metadata

CVE search record: CVE-2026-104069. Severity: high. CVSS: 7.2. KEV: no. Product: HortusFox (< 6.2). Brief: Remote Code Execution in HortusFox ThemeModule. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-104069/

HortusFox versions prior to 6.2 are affected by a remote code execution vulnerability located within the ThemeModule::startImport() function. The vulnerability stems from an insecure file handling implementation where uploaded ZIP archives are extracted directly into the application's public web root. Critically, the system performs no validation on the file names, extensions, or content of the extracted files prior to placement in an executable directory. An authenticated administrator can leverage this by uploading a specially crafted theme archive containing both a malicious PHP script and an .htaccess file, which bypasses typical execution restrictions. By subsequently requesting the uploaded file via the themes directory, an attacker can execute arbitrary OS commands under the privileges of the web-server user.

Attack Chain

  1. Authenticated attacker logs into the HortusFox administrative interface.
  2. Attacker prepares a ZIP archive containing a PHP web shell and a custom .htaccess configuration file.
  3. Attacker navigates to the theme import feature and uploads the crafted ZIP archive.
  4. The application processes the upload through the vulnerable ThemeModule::startImport() function.
  5. The application extracts the contents of the ZIP archive directly into the public web root directory without validation.
  6. The .htaccess file is applied by the web server, enabling PHP execution for the attacker's script if previously restricted.
  7. Attacker requests the path to the uploaded PHP shell via a standard HTTP GET request.
  8. Web server executes the PHP script, providing the attacker with remote command execution capabilities.

Impact

Successful exploitation of this vulnerability allows an authenticated administrator to achieve full remote code execution on the underlying server. This results in complete compromise of the web application, potential lateral movement within the network, and access to sensitive data stored on or accessible to the web server process. The scope is limited to HortusFox instances running version 6.1 or earlier.

Recommendation

  1. Upgrade all HortusFox installations to version 6.2 or later immediately to patch the vulnerable ThemeModule::startImport() function.
  2. Implement strict file system permissions on the public web root to prevent the web server process from writing new executable files in directories where they are not required.
  3. Deploy file integrity monitoring on the /themes directory to alert on the creation of unexpected .php or .htaccess files.
  4. Enable and monitor web server access logs for requests to non-standard or unexpected files within the /themes directory structure.

Immediate actions

Upgrade HortusFox to 6.2 or later

IT Operations 24h

Mitigations

Restrict web server write permissions to the themes directory

immediate IT Operations

CVE-2026-104069

Detection coverage 1

Detect Suspicious File Creation in HortusFox Themes Directory

high

Detects the creation of .php or .htaccess files within the HortusFox themes directory, which is a primary indicator of CVE-2026-104069 exploitation

sigma tactics: execution, persistence techniques: T1059.003 sources: file_event

Detection queries are available on the platform. Get full rules →