Kunstmaan MediaBundle Blacklist Bypass Leading to Remote Code Execution
An authentication-required blacklist bypass vulnerability in the Kunstmaan MediaBundle allows malicious administrators to upload arbitrary executable files via case-sensitive extension filtering, resulting in remote code execution.
CVE search metadata
CVE search record: CVE-2026-104890. Severity: high. CVSS: 7.2. EPSS: 0.42%. KEV: no. Product: MediaBundle (< 7.3.2), Bundles-CMS (< 7.3.2). Brief: Kunstmaan MediaBundle Blacklist Bypass Leading to Remote Code Execution. Brief link: https://feed.craftedsignal.io/briefs/2026-10-kunstmaan-cms-rce/
Kunstmaan MediaBundle versions prior to 7.3.2 are vulnerable to a remote code execution (RCE) flaw due to improper handling of uploaded file extensions. The application employs a blacklist to prevent the upload of dangerous file types (e.g., .php, .htaccess); however, the validation logic performs a case-sensitive check before the file extension is normalized to lowercase. An attacker with authenticated administrator access to the media management section can bypass this filter by uploading a file with mixed-case extensions (e.g., .pHp).
The vulnerability is further exacerbated by an incomplete default blacklist that fails to cover common executable extensions such as .phtml, .php5, .phar, .shtml, and .cgi, as well as insecure regex interpolation. Once uploaded, these files are saved to a web-accessible directory and can be executed by the web server. This vulnerability, tracked as CVE-2026-104890, necessitates an immediate upgrade to version 7.3.2 or higher, along with an audit of existing upload directories for previously stored malicious files.
Attack Chain
- Attacker gains authentication as a user with administrative access to the media management section of the Kunstmaan CMS.
- Attacker crafts a malicious payload file with an unconventional casing for an executable extension (e.g.,
shell.pHp). - Attacker submits the file via the MediaBundle upload interface.
- The application performs a case-sensitive regex check against the blacklist, which fails to flag the mixed-case extension.
- The application normalizes the filename to lowercase, inadvertently turning the file into a valid executable format (e.g.,
shell.php) on the filesystem. - The web server processes the uploaded file from the web-accessible directory.
- The attacker executes the file over HTTP, resulting in remote code execution under the privileges of the web server process.
Impact
Successful exploitation grants an authenticated administrator arbitrary code execution on the underlying host. This allows for full system compromise, data exfiltration, or lateral movement within the environment. Because the vulnerability requires administrative access, the primary risk is from compromised accounts or malicious insiders.
Recommendation
- Upgrade the kunstmaan/media-bundle and kunstmaan/bundles-cms packages to version 7.3.2 or later immediately to address CVE-2026-104890.
- Audit the web-accessible media upload directory for existing files containing executable extensions (.php, .phtml, .php5, .phar, .shtml, .cgi) to identify potential prior exploitation.
- Implement web server-level restrictions (e.g., disabling PHP execution in the upload directory) as a compensating control if immediate patching is not possible.
Immediate actions
Patch Kunstmaan MediaBundle to 7.3.2 or later
Threat Hunt
Search web server access logs for requests to file extensions in the media directory
Data: webserver log entries
Mitigations
Disable PHP engine in media upload directories at the web server level
CVE-2026-104890