Exploitation Summary
EIP tracks 3 public exploits for CVE-2026-21628. PoCs published by adminlove520, ChiefYoru, webshellseo8.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-21628, targeting an unauthenticated RCE vulnerability in the Astroid Framework. The exploit leverages SVG file uploads to bypass MIME checks and achieve remote code execution.
Description
A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.
Exploits (3)
This repository contains a functional exploit for CVE-2026-21628, targeting an unauthenticated RCE vulnerability in the Astroid Framework. The exploit leverages SVG file uploads to bypass MIME checks and achieve remote code execution.
This exploit targets an unauthenticated remote code execution (RCE) vulnerability in the Astroid Framework for Joomla. It abuses the media upload and rename functionality via com_ajax to upload a malicious SVG file and rename it to a PHP webshell, achieving arbitrary code execution.
This repository contains a functional exploit for CVE-2026-21628, targeting an unauthenticated RCE vulnerability in the Astroid Framework. The exploit leverages SVG file uploads to bypass MIME checks and achieve remote code execution by uploading a malicious PHP shell.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H