CVE-2026-34415 is a critical input validation vulnerability affecting Xerte Online Toolkits version 3.15 and earlier in the elFinder connector endpoint. The flaw allows unauthenticated attackers to bypass file upload restrictions by exploiting an incomplete regex pattern that fails to block the .php4 executable extension. When combined with authentication bypass and path traversal weaknesses, attackers can upload malicious PHP code, rename it with a .php4 extension, and execute arbitrary operating system commands on vulnerable servers. The vulnerability carries a CVSS 3.1 severity score of 9.8 (CRITICAL) with a network-based attack vector requiring no authentication or user interaction, resulting in complete compromise of system confidentiality, integrity, and availability. The attack complexity is low, making exploitation straightforward for threat actors with basic technical knowledge. While CVE-2026-34415 is not currently listed in CISA's Known Exploited Vulnerabilities catalog, it is flagged as active on vulnerability hotlists and represents a significant risk requiring immediate patching. Organizations running affected Xerte versions should prioritize remediation given the critical severity rating and the remote, unauthenticated nature of the attack vector.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Thexerteproject | Xerteonlinetoolkits | >= 0, <= 3.15.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.