AI description
CVE-2026-100520 is a path traversal vulnerability affecting Laranode, a multi-tenant application, in versions prior to 1.2.1. The issue resides in the `POST /filemanager/upload-file` endpoint, which is used for file management operations. It allows authenticated users to write arbitrary files outside of their designated home directory by manipulating the file upload path. To exploit this vulnerability, an attacker can input directory traversal sequences into the `path` parameter during a file upload. This allows them to write PHP files into the web roots of other tenants, leading to arbitrary code execution under the context of those tenants. The vulnerability has been resolved in Laranode version 1.2.1.
- Description
- Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants.
- Source
- disclosure@vulncheck.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 8.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- disclosure@vulncheck.com
- CWE-22
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
7
CVE-2026-100520 now has a new public exploit. Laranode <1.2.1 allows authenticated users to write PHP files into other tenants' web roots, potentially leading to RCE. CVSS 8.7 | EPSS 0.94% ExploitGrid Score: 35.2/100 Full intel: https://t.co/bZdTY9ijyi #CyberSecurity #CVE #R
@exploitgrid
3 Oct 2026
25 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
🚨 Public PoC released for CVE-2026-100520 affecting Laranode https://t.co/ijybWz35Pc CVE-2026-100520 is a high-severity path traversal flaw in the Laranode multi-tenant hosting control panel that can let a low-privileged authenticated user write files outside their own home
@DarkWebInformer
3 Oct 2026
3873 Impressions
3 Retweets
16 Likes
7 Bookmarks
0 Replies
0 Quotes