What is CVE-2026-48939?
CVE-2026-48939 is a critical vulnerability in iCagenda caused by unrestricted file upload. This flaw allows attackers to upload arbitrary PHP files via the attachment feature, leading to remote code execution. iCagenda users must immediately apply the latest security update.
Azərbaycanca: CVE-2026-48939, iCagenda komponentində fayl yükləmə məhdudiyyətinin olmaması səbəbindən yaranan kritik zəiflikdir. Bu boşluq hücumçulara ixtiyari PHP faylları yükləyərək uzaqdan kod icrasına imkan verir. iCagenda istifadəçiləri dərhal ən son təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
What risk does CVE-2026-48939 pose in iCagenda?
This vulnerability allows attackers to upload arbitrary PHP files, leading to remote code execution (RCE).
How can users protect themselves from CVE-2026-48939?
iCagenda users must immediately apply the latest security update.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.