CVE-2026-1126 describes an unrestricted file upload vulnerability in the SVG File Handler component of lwj flow, specifically within the uploadFile function. This flaw allows an authenticated remote attacker to upload arbitrary files, potentially leading to information disclosure, modification, or denial of service. With a CVSS score of 6.3 (Medium), the attack is network-based and low complexity, requiring low privileges and no user interaction. While the exploit has been publicly disclosed, there is no evidence of active exploitation, and no known exploit intelligence or significant community discussion has been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Lwj | Flow | a3d2fe8133db9d3b50fda4f66f68634640344641CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.