CVE-2026-19852
Received Received - Intake

Arbitrary File Upload in NewSiteServer

Vulnerability report for CVE-2026-19852, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: TWCERT/CC

Description

NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cybertutor newsiteserver *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

NewSiteServer (NSS) by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload any file, including malicious HTML files, which may lead to cross-site scripting (XSS) attacks.

Detection Guidance

Since this is an arbitrary file upload vulnerability in NewSiteServer (NSS), detection involves monitoring for unexpected file uploads or suspicious file types. Check server logs for POST requests to upload endpoints, especially for files with .html, .php, or other executable extensions. Inspect directories where uploads are stored for unauthorized files. Use network traffic analysis tools like Wireshark to detect unusual outbound connections from the server.

Impact Analysis

Attackers could upload malicious files to the server, potentially executing scripts in users' browsers. This could lead to data theft, session hijacking, or defacement of the website. The impact depends on the server's configuration and user interactions.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information. Organizations may face compliance penalties if exploited.

Mitigation Strategies

Contact the vendor CyberTutor for patches or mitigations immediately. Avoid using NewSiteServer (NSS) until a fix is applied to prevent unauthorized file uploads and potential XSS attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19852. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart