CVE-2026-48062: CodeIgniter File Upload Validation Bypass (CVSS 9.8)
ID: 69c44f76-abe2-5de0-aba8-71e4d74eb1d2
STIX ID: report--69c44f76-abe2-5de0-aba8-71e4d74eb1d2
Feed Name: CosmicBytez Labs
Threat Score
A critical CodeIgniter file-upload validation bypass (CVE-2026-48062, CVSS 9.8) allows attackers to prepend image magic bytes to PHP web shells so they pass ext_in validation and are stored/executed as PHP, resulting in remote code execution; affected versions are CodeIgniter < 4.7.3 — upgrade to 4.7.3 or apply mitigations (disable uploads, block PHP execution in upload dirs, store uploads outside web root).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
