{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/kunstmaan/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-104890"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MediaBundle (\u003c 7.3.2)","Bundles-CMS (\u003c 7.3.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Kunstmaan"],"content_html":"\u003cp\u003eKunstmaan MediaBundle versions prior to 7.3.2 are vulnerable to a remote code execution (RCE) flaw due to improper handling of uploaded file extensions. The application employs a blacklist to prevent the upload of dangerous file types (e.g., .php, .htaccess); however, the validation logic performs a case-sensitive check before the file extension is normalized to lowercase. An attacker with authenticated administrator access to the media management section can bypass this filter by uploading a file with mixed-case extensions (e.g., .pHp).\u003c/p\u003e\n\u003cp\u003eThe vulnerability is further exacerbated by an incomplete default blacklist that fails to cover common executable extensions such as .phtml, .php5, .phar, .shtml, and .cgi, as well as insecure regex interpolation. Once uploaded, these files are saved to a web-accessible directory and can be executed by the web server. This vulnerability, tracked as CVE-2026-104890, necessitates an immediate upgrade to version 7.3.2 or higher, along with an audit of existing upload directories for previously stored malicious files.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains authentication as a user with administrative access to the media management section of the Kunstmaan CMS.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload file with an unconventional casing for an executable extension (e.g., \u003ccode\u003eshell.pHp\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAttacker submits the file via the MediaBundle upload interface.\u003c/li\u003e\n\u003cli\u003eThe application performs a case-sensitive regex check against the blacklist, which fails to flag the mixed-case extension.\u003c/li\u003e\n\u003cli\u003eThe application normalizes the filename to lowercase, inadvertently turning the file into a valid executable format (e.g., \u003ccode\u003eshell.php\u003c/code\u003e) on the filesystem.\u003c/li\u003e\n\u003cli\u003eThe web server processes the uploaded file from the web-accessible directory.\u003c/li\u003e\n\u003cli\u003eThe attacker executes the file over HTTP, resulting in remote code execution under the privileges of the web server process.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an authenticated administrator arbitrary code execution on the underlying host. This allows for full system compromise, data exfiltration, or lateral movement within the environment. Because the vulnerability requires administrative access, the primary risk is from compromised accounts or malicious insiders.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the kunstmaan/media-bundle and kunstmaan/bundles-cms packages to version 7.3.2 or later immediately to address CVE-2026-104890.\u003c/li\u003e\n\u003cli\u003eAudit the web-accessible media upload directory for existing files containing executable extensions (.php, .phtml, .php5, .phar, .shtml, .cgi) to identify potential prior exploitation.\u003c/li\u003e\n\u003cli\u003eImplement web server-level restrictions (e.g., disabling PHP execution in the upload directory) as a compensating control if immediate patching is not possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:53:43Z","date_published":"2026-10-07T22:53:43Z","id":"https://feed.craftedsignal.io/briefs/2026-10-kunstmaan-cms-rce/","summary":"An authentication-required blacklist bypass vulnerability in the Kunstmaan MediaBundle allows malicious administrators to upload arbitrary executable files via case-sensitive extension filtering, resulting in remote code execution.","title":"Kunstmaan MediaBundle Blacklist Bypass Leading to Remote Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-10-kunstmaan-cms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Kunstmaan","version":"https://jsonfeed.org/version/1.1"}