Answer in brief
CVE-2026-104890 records a High severity (CVSS 7.2) vulnerability in Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution. The current sources do not mark it as known exploited. The current feed maps kunstmaan/bundles-cms (generic), Kunstmaan/KunstmaanBundlesCMS (generic), kunstmaan/media-bundle (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.2. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps kunstmaan/bundles-cms (generic), Kunstmaan/KunstmaanBundlesCMS (generic), kunstmaan/media-bundle (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| kunstmaan/bundles-cmsgeneric | <7.3.1 | 7.3.1 |
| Kunstmaan/KunstmaanBundlesCMSgeneric | <7.3.1 | 7.3.1 |
| kunstmaan/media-bundlegeneric | <7.3.1 | 7.3.1 |
Published upstream
Oct 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 5, 2026
Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend user with media access can upload a mixed-case executable extension such as PHP that bypasses the check and is stored in the web-accessible media directory with an executable lowercase extension. The default blacklist also omits several server-executable extension types, allowing the same code-execution impact where the web server executes uploaded files. This issue is fixed in version 7.3.2.
Quoted source text, attributed separately from HOL analysis.