Vulnerability Description
Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint. Attackers can upload executable files .php5 scripts to web-accessible directories and execute them to achieve remote code execution on the server.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.vulncheck.com/advisories/pachno-unrestricted-file-upload-remote-code
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5982.php
FAQ
What is CVE-2026-40040?
CVE-2026-40040 is a vulnerability with a CVSS score of 8.8 (HIGH). Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint....
How severe is CVE-2026-40040?
CVE-2026-40040 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-40040?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.