logo

CVE-2026-15488: Unrestricted File Upload in shiroiAdmin Enables Remote Code Execution

ID: 06e9a234-ce73-5981-8fd5-25e5efd46761

STIX ID: report--06e9a234-ce73-5981-8fd5-25e5efd46761

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-07-12

Date Updated: 2026-07-13

...
...

**CVE-2026-15488**: Unrestricted file upload in shiroiAdmin 1.1 and 1.3 allows unauthenticated attackers to upload PHP webshells and obtain remote code execution (CVSS 7.3); the report includes vulnerable code excerpts, a public proof-of-concept exploit, indicators of exposure, SIEM/WAF detection rules, and remediation options.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.