Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34413

53
FAUCET Score

OVERVIEW Xerte Online Toolkits versions 3.15 and earlier contain a critical authentication bypass vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php. The flaw exists because HTTP redirects to unauthenticated users fail to terminate PHP execution, allowing requests to continue processing server-side. This permits unauthenticated attackers to perform unauthorized file operations including uploading, creating, renaming, deleting, and overwriting files in project media directories. SEVERITY The vulnerability carries a CVSS score of 8.6 (HIGH) with a network-based attack vector requiring no authentication or user interaction. Attack complexity is low, indicating exploitation is straightforward. The impact is significant: attackers can manipulate files on the server, and when chained with path traversal and extension blocklist bypass vulnerabilities, achieve remote code execution and read arbitrary files. The FAUCET Risk Score of 51.0/100 reflects elevated concern within the security community. EXPLOITATION STATUS The vulnerability is currently active on threat tracking lists and warrants immediate attention, though it does not appear in the Known Exploited Vulnerabilities catalog. The relatively low EPSS score of 0.003 suggests limited current exploitation in the wild compared to other CVEs. However, the straightforward nature of the authentication bypass and high potential impact make this a priority for patching, particularly for organizations running affected Xerte versions in internet-facing environments.

Impacted Technologies

VendorProductVersion(s)CPE
ThexerteprojectXerteonlinetoolkits
>= 0, <= 3.15.0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

8.8HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
HIGH
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
3.11%
Probability of exploitation in next 30 days
EPSS Percentile
86.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload · Apr 22, 2026
Nuclei: CVE-2026-34413 · Jun 21, 2026
This CVE's current EPSS score of 0.0311 is in the 76th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / bootstrapbool/xerteonlinetoolkits-rce
github.com / thexerteproject/xerteonlinetoolkits/commit/02661be88cc369325ea01b508086bde7fbfec805
github.com / thexerteproject/xerteonlinetoolkits/commit/17e4f945fe6a3400fa88c01eda18c1075ee4a212
github.com / thexerteproject/xerteonlinetoolkits/commit/507d55c5e91bf9310b5b1c7fad8aebfef902ad23
github.com / thexerteproject/xerteonlinetoolkits/issues/1527
vulncheck.com / advisories/xerte-online-toolkits-missing-authentication-via-connector-php
xerte.org.uk / index.php/en/downloads-1/category/3-xerte-online-toolkits
xerte.org.uk / xertetoolkits_3.15_ChangeLog.html