SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-75496

HIGH · CVSS 7.2 EPSS 0.53% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Webkul QloApps is vulnerable due to inadequate validation of uploaded file extensions and MIME types, allowing authenticated attackers with administrative privileges to upload malicious executable files to a publicly accessible directory. This flaw can lead to remote code execution, posing a significant risk to the integrity and security of the application. Organizations using QloApps should prioritize patching this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75496
Severity
HIGH
CVSS
7.2
EPSS
0.53%

Original NVD Description

Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.