CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-94278: File Media Renamer 0 through 1.3

CVE-2026-94278. CVSS 3.1 base score 5.5 (MEDIUM, Source advisory).

Affected technology

File Media Renamer · 0 through 1.3
Vendor not specified by the source

Description’s affected range: through 1.3 does not verify that the requesting user is authorised to modify a given media attachment

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · High privileges required · No user interaction required

What an attacker can do

Any user with file-upload privileges to rename attachments belonging can other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path. Source advisory’s CVSS 3.1 assessment (base score 5.5/10) rates confidentiality impact as none; integrity impact as high; availability impact as low.

Published

CWE
CWE-284
CCR priority
22.0 /100 (P4)
CVSS 3.1
5.5 /10 · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L · Source advisory
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-94278.html