---
id: CVE-2026-5695
title: >-
  Arbitrary file upload vulnerability due to a lack of proper validation in
  upload forms
summary: >-
  Arbitrary file upload vulnerability due to a lack of proper validation in
  upload forms. This allows authenticated users to upload files to the server
  without restrictions. An attacker could exploit this flaw to execute malicious
  code rem…
severity: high
cvss: 8.4
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-434
vendor: Microweber
product: Administration panel
affected:
  - administration_panel 2.0.19
published: '2026-09-23'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:45:22.827'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5695'
references:
  - url: >-
      https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-microweber-administration-panel
    label: cve-coordination@incibe.es
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-23T13:46:21.222532Z'
cvssSource: cna
ingestedAt: '2026-09-23T11:22:32.913Z'
epss: 0.00298
epssPercentile: 0.19978
---

## Overview

Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
