References https://bdziyi.com/66961/ https://www.gm7.org/archives/77851 https://nvd.nist.gov/vuln/detail/CVE-2026-2330 https://access.redhat.com/security/cve/cve-2026-2330 https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0006.pdf https://www.sans.org/newsletters/at-risk/xxvi-10 https://www.thehackerwire.com/crown-rest-critical-file-modification-via-whitelist-bypass/ https://www.cve.org/CVERecord?id=CVE-2026-2330
Related VulnerabilitiesCuteHttpFileServer/chfs存在未授权任意文件上传PoCCVE-2026-0717: LottieFiles for Gutenberg <= 3.0.0 - Unauthenticated Settings DisclosurePoCCVE-2026-57827: RSFiles! for Joomla - Arbitrary File UploadCisco ISE /admin/files-upload/ 文件上传漏洞(CVE-2025-20282)MicroweberCMS userfiles x存在路径穿越漏洞(CVE-2026-65694)Langflow /api/v2/files 文件上传漏洞(CVE-2026-5027)易宝OA /api/files/DownloadFile2 文件读取漏洞PoCfilestash-installer: Filestash - Installer ExposurePoCCVE-2025-68043: LottieFiles WordPress Plugin <= 3.0.0 - Missing Authorization天锐绿盾审批系统 /trwfe/login.jsp/.%2e/rest/ext/fileServer 信息泄露漏洞Gladinet CentreStack & Triofox /storage/filesvr.dn 文件读取漏洞(CVE-2025-14611)WordPress LottieFiles /wp-json/lottiefiles/v1/settings/ 权限绕过漏洞(CVE-2025-68043)Langflow /api/v1/files/profile_pictures/../secret_key 文件读取漏洞(CVE-2026-33497)