---
id: CVE-2026-36467
title: >-
  Unrestricted Upload of File with Dangerous Type in core/modules/media.php in
  CuteNews v.2.1.2 allows remote authenticated users with access to the Media
  Manager panel to execute arbitrary code in the context of the web application,
  leadi…
summary: >-
  Unrestricted Upload of File with Dangerous Type in core/modules/media.php in
  CuteNews v.2.1.2 allows remote authenticated users with access to the Media
  Manager panel to execute arbitrary code in the context of the web application,
  leadi…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
published: '2026-09-21'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:00:03.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-36467'
references:
  - url: 'https://github.com/CuteNews/cutenews-2.0'
    label: cve@mitre.org
  - url: >-
      https://github.com/CuteNews/cutenews-2.0/blob/master/core/modules/media.php
    label: cve@mitre.org
  - url: 'https://github.com/UmbraDeorum/cutenews-2.0-CVEs-2026-Disclosure'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
epss: 0.00981
epssPercentile: 0.60674
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-21T15:50:44.971213Z'
ingestedAt: '2026-09-21T16:11:47.442Z'
---

## Overview

Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
