CVE-2026-15488: Unrestricted File Upload in shiroiAdmin Enables Remote Code Execution
ID: 06e9a234-ce73-5981-8fd5-25e5efd46761
STIX ID: report--06e9a234-ce73-5981-8fd5-25e5efd46761
Feed Name: CosmicBytez Labs
Threat Score
**CVE-2026-15488**: Unrestricted file upload in shiroiAdmin 1.1 and 1.3 allows unauthenticated attackers to upload PHP webshells and obtain remote code execution (CVSS 7.3); the report includes vulnerable code excerpts, a public proof-of-concept exploit, indicators of exposure, SIEM/WAF detection rules, and remediation options.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
