EUVD-2026-63217
A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
- ENISA score
- 8.6 · CVSS 4.0
- Advisory evidence
- No linked advisory details stored yet
