Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 29 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename in the ZIP archive, which is stored in the public web root and executed by unauthenticated requests. | |
| Title | BookStack before 26.05.4 Remote Code Execution via Book Cover | |
| First Time appeared |
Bookstackapp
Bookstackapp bookstack |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:bookstackapp:bookstack:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Bookstackapp
Bookstackapp bookstack |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T13:47:53.312Z
Reserved: 2026-08-29T13:22:57.885Z
Link: CVE-2026-82450
No data.
Status : Received
Published: 2026-08-29T14:16:37.930
Modified: 2026-08-29T14:16:37.930
Link: CVE-2026-82450
No data.
OpenCVE Enrichment
Updated: 2026-08-29T16:00:03Z
-
CWE-434
Unrestricted Upload of File with Dangerous Type