CVE-2026-2334
Received Received - Intake

Authenticated File Upload Bypass Leading to RCE in vsDesk

Vulnerability report for CVE-2026-2334, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: Kaspersky Labs

Description

An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application.Β  Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
vsdesk vsdesk to 14.0402 (exc)
vsdesk vsdesk From 14.0402 (inc)
vsdesk vsdesk 14.0101

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in vsDesk v14.0101 allows an authenticated admin to bypass client-side file validation when using the 'Import via CSV' feature. The lack of server-side validation enables uploading arbitrary files, which can lead to Remote Code Execution (RCE) within the web application's context.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized file uploads or suspicious activity in the vsDesk CSV import feature. Monitor server logs for unexpected file types or paths during CSV imports. Look for administrative actions involving file uploads outside expected formats.

Impact Analysis

An attacker with admin access could exploit this to upload malicious files, potentially gaining control over the vsDesk server. This could lead to data theft, system compromise, or disruption of services. The impact depends on the application's role in your infrastructure.

Compliance Impact

This vulnerability could lead to unauthorized access, data breaches, or loss of sensitive data, violating GDPR (data protection) and HIPAA (healthcare data privacy) requirements. Organizations using affected vsDesk versions may face compliance penalties and reputational damage.

Mitigation Strategies

Immediately update vsDesk to version 14.0402 or later from the vendor's website. Ensure server-side validation is enforced for all file uploads, especially CSV imports. Review and restrict administrative privileges to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-2334. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart