CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-34415

Critical · CVSS 9.8

Xerte Online Toolkits — Incomplete input validation / unrestricted file upload leading to RCE (authentication bypass + path traversal + PHP extension bypass)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-184

Description

Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern. Unauthenticated attackers can exploit this flaw combined with authentication bypass and path traversal vulnerabilities to upload malicious PHP code, rename it with a .php4 extension, and execute arbitrary operating system commands on the server.

Search profile — drives PoC discovery

Symbols elFinderelFinder connectorphp4regex patternauthentication bypasspath traversalfile uploadrename.php4 extensionbootstrapbool/xerteonlinetoolkits-rce
Keywords CVE-2026-34415Xerte Online Toolkits RCEelFinder connector PHP upload bypassxerteonlinetoolkits php4 extension bypassXerte file upload vulnerabilityXerte authentication bypass path traversalCWE-184 incomplete blocklist Xertexerteonlinetoolkits-rce PoC
Versions: ≤ 3.15

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z