What is CVE-2026-53599?
CVE-2026-53599 is a critical vulnerability in REDAXO CMS affecting versions 5.18.2 through 5.21.1, where the `isAllowedExtension` check in mediapool can be bypassed. An authenticated backend user with upload permissions can upload a JPEG/PHP polyglot file, potentially leading to remote code execution. Immediate update to the latest version is strongly advised.
Azərbaycanca: CVE-2026-53599 REDAXO CMS-də aşkarlanmış kritik zəiflikdir. 5.18.2-dən 5.21.1-ə qədər versiyalarda, media yükləmə icazəsi olan autentifikasiya olunmuş istifadəçi JPEG/PHP polyglot faylı (`shell.php.any.jpg`) yükləyərək ixtiyari kod icrasına nail ola bilər. Dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which versions of REDAXO CMS are affected by CVE-2026-53599?
This vulnerability affects REDAXO CMS versions 5.18.2 through 5.21.1.
What level of access is required to exploit CVE-2026-53599?
Exploitation requires an authenticated backend user account with upload permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.