CVE-2026-92247
Received Received - Intake

Unrestricted File Upload in SynaptikCMS Admin Component

Vulnerability report for CVE-2026-92247, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: VulDB

Description

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin File Manager. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.3.5 is able to mitigate this issue. It is suggested to upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
synaptikcms synaptik-cms to 1.3.4.4 (inc)
synaptikcms synaptik-cms 1.3.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authenticated Remote Code Execution (RCE) flaw in SynaptikCMS's File Manager component. It allows an authenticated attacker with admin access to upload a file with a non-PHP filename, then rename it to a PHP file. This places executable PHP code in a web-accessible location, enabling remote code execution under the web server's privileges.

Detection Guidance

Check for unauthorized PHP files in web-accessible directories, particularly in the SynaptikCMS file manager. Look for files with non-PHP extensions that were renamed to .php. Review server logs for suspicious file upload or rename operations in the admin/file-manager.php component.

Impact Analysis

Exploitation can lead to arbitrary command execution, potentially compromising the application, accessing server-side files, modifying data, or further compromising the underlying server. Attackers could gain full control over the affected system.

Mitigation Strategies

Upgrade SynaptikCMS to version 1.3.5 or later immediately. Remove any unauthorized PHP files in web-accessible directories. Restrict administrative access to the file manager. Monitor for suspicious activity in server logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92247. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart