CVE-2026-2334
Received
Received - Intake
Authenticated File Upload Bypass Leading to RCE in vsDesk
Vulnerability report for CVE-2026-2334, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-20
Last updated on: 2026-08-20
Assigner: Kaspersky Labs
Description
Description
An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application.Β
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| vsdesk | vsdesk | to 14.0402 (exc) |
| vsdesk | vsdesk | From 14.0402 (inc) |
| vsdesk | vsdesk | 14.0101 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |