CVE-2026-53691

HIGH

Remote Code Execution in Redeight CMS

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-53691. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-53691, an unrestricted file upload vulnerability in Redeight CMS 1.0. The code includes metadata and placeholder methods but lacks actual exploit implementation, referencing an external link for details.

Description

An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST "/admin/index.php?module=pages&mode=FileAdd" endpoint. The application fails to validate file extensions and MIME types, permitting the upload of arbitrary PHP scripts to the publicly accessible "/uploads/files/" directory where they can be executed directly by the web server.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-53691_unrestricted_file_upload.py

This repository contains an auto-generated stub module for CVE-2026-53691, an unrestricted file upload vulnerability in Redeight CMS 1.0. The code includes metadata and placeholder methods but lacks actual exploit implementation, referencing an external link for details.

Classification
Stub 99%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Redeight CMS version 1.0
Auth required
Prerequisites: Authenticated access to the CMS admin panel · Ability to reach the vulnerable endpoint "/admin/index.php?module=pages&mode=FileAdd"
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory third-party-advisory
https://cert.pl/posts/2026/06/CVE-2026-53690

Scores

CVSS v4 8.6
EPSS 0.0049
EPSS Percentile 39.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
Redeight/Redeight CMS 1.0
Published Jun 30, 2026
Tracked Since Jun 30, 2026