CVE-2026-2146 is an unrestricted file upload vulnerability in guchengwuyue yshopmall up to version 1.9.1, specifically within the updateAvatar function of the /api/users/updateAvatar endpoint. This flaw allows a remote attacker to upload arbitrary files by manipulating the 'File' argument, potentially leading to severe impacts on confidentiality, integrity, and availability. With a CVSS score of 8.8 (HIGH) and a FAUCET Risk Score of 94/100, this vulnerability is critical. Although no active exploitation has been observed, a public exploit has been released, increasing the risk of future attacks. There is currently no community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.9.1CPE matchmatch criteria | cpe:2.3:a:guchengwuyue:yshopmall:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.