Loading market data...
← Back to CVE feed

CVE-2026-80050

MEDIUM CVSS 6.5 View on NVD ↗

Description

ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. Attackers can initialize chunked uploads, send file parts, and complete uploads to leave arbitrary files in the storage backend accessible via web server URLs.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Published: Aug 25, 2026 19:16 UTC Modified: Aug 26, 2026 14:17 UTC