Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34415

49
FAUCET Score

CVE-2026-34415 is a critical input validation vulnerability affecting Xerte Online Toolkits version 3.15 and earlier in the elFinder connector endpoint. The flaw allows unauthenticated attackers to bypass file upload restrictions by exploiting an incomplete regex pattern that fails to block the .php4 executable extension. When combined with authentication bypass and path traversal weaknesses, attackers can upload malicious PHP code, rename it with a .php4 extension, and execute arbitrary operating system commands on vulnerable servers. The vulnerability carries a CVSS 3.1 severity score of 9.8 (CRITICAL) with a network-based attack vector requiring no authentication or user interaction, resulting in complete compromise of system confidentiality, integrity, and availability. The attack complexity is low, making exploitation straightforward for threat actors with basic technical knowledge. While CVE-2026-34415 is not currently listed in CISA's Known Exploited Vulnerabilities catalog, it is flagged as active on vulnerability hotlists and represents a significant risk requiring immediate patching. Organizations running affected Xerte versions should prioritize remediation given the critical severity rating and the remote, unauthenticated nature of the attack vector.

Impacted Technologies

VendorProductVersion(s)CPE
ThexerteprojectXerteonlinetoolkits
>= 0, <= 3.15.0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
3.57%
Probability of exploitation in next 30 days
EPSS Percentile
88.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload · Apr 22, 2026
This CVE's current EPSS score of 0.0357 is in the 81st percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / bootstrapbool/xerteonlinetoolkits-rce
github.com / thexerteproject/xerteonlinetoolkits/commit/02661be88cc369325ea01b508086bde7fbfec805
github.com / thexerteproject/xerteonlinetoolkits/commit/17e4f945fe6a3400fa88c01eda18c1075ee4a212
github.com / thexerteproject/xerteonlinetoolkits/commit/507d55c5e91bf9310b5b1c7fad8aebfef902ad23
github.com / thexerteproject/xerteonlinetoolkits/issues/1527
vulncheck.com / advisories/xerte-online-toolkits-file-upload-rce-via-elfinder-connector
xerte.org.uk / index.php/en/downloads-1/category/3-xerte-online-toolkits
xerte.org.uk / xertetoolkits_3.15_ChangeLog.html