{"id":"CVE-2026-53599","title":"REDAXO is a PHP-based content management system","summary":"REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-434"],"vendor":"redaxo","product":"redaxo/source","affected":["redaxo/source >= 5.18.2, < 5.21.1"],"patched":["redaxo/source 5.21.1"],"published":"2026-07-31","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:55:04.493","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53599","references":[{"url":"https://github.com/redaxo/core/commit/462e36896bb65d292ba22d711044c23c9cfb0340","label":"security-advisories@github.com"},{"url":"https://github.com/redaxo/core/pull/6538","label":"security-advisories@github.com"},{"url":"https://github.com/redaxo/core/releases/tag/5.21.1","label":"security-advisories@github.com"},{"url":"https://github.com/redaxo/core/security/advisories/GHSA-98pp-vccm-qm25","label":"security-advisories@github.com"},{"url":"https://github.com/redaxo/core/security/advisories/GHSA-98pp-vccm-qm25","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-98pp-vccm-qm25"}],"tags":["nvd","ghsa","composer"],"epss":0.00395,"epssPercentile":0.33472,"aliases":["GHSA-98pp-vccm-qm25"],"ecosystem":"composer","ingestedAt":"2026-07-31T20:02:42.843Z","slug":"CVE-2026-53599","body":"## Overview\n\nREDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polyglot named shell.php.any.jpg, which web servers with multi-extension PHP handlers can execute as the web-server user. This issue is fixed in version 5.21.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-53599)\n\nAffected packages:\n\n- `redaxo/source >= 5.18.2, < 5.21.1`\n\nPatched in:\n\n- `redaxo/source 5.21.1`\n\nSource: https://github.com/advisories/GHSA-98pp-vccm-qm25","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}