Critical Vulnerability Report: Unauthenticated File Upload Bypass Leading to RCE (CVSS 9.8)

1

To the Webasyst Security Team,

We are privately disclosing a critical vulnerability found in the Webasyst Framework during authorized security testing.

Title: Unauthenticated File Upload Bypass Leading to Remote Code Execution
Severity: Critical (CVSS 9.8 — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected Product: Webasyst Framework
Discovered: April 26, 2026

Summary: Insufficient content validation on the file upload endpoint, combined with the rename endpoint allowing extension changes to executable types (.phar, .php, .phtml), lets an attacker upload a disguised payload and trigger remote code execution as the web server user.

We have a full technical report with proof-of-concept and remediation recommendations ready to share through a secure private channel. Please confirm receipt and let us know your preferred channel for the full writeup.

Regards,
Abdulrahman Aldossary, Saleh Algamdi
Security Researchers
afaldossary32@gmail.com

0 comments

    Add comment

    To add a comment please sign up or login