Sceawere
Vulnerability Detail
CVE-2026-94503UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Zombify Unrestricted File Upload Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 3h ago
- Vendor
- PX-lab
- Product
- Zombify
- Attack Type
- Unrestricted Upload of File with Dangerous Type
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-10-09T10:16:40.607Z",
"pubdate": "2026-10-09T10:16:40.607Z",
"executiveSummary": "The Zombify application, developed by PX-lab, is susceptible to an Unrestricted Upload of File with Dangerous Type vulnerability. This flaw exists in all versions from n/a through 1.7.7.\nThe vulnerability originates from the application's failure to adequately validate or restrict the file types permitted during the upload process. An attacker can exploit this by uploading malicious files, such as web shells, directly to the web server.\nSuccessful exploitation grants an unauthorized attacker the ability to execute arbitrary code within the context of the web server process. This poses a critical risk to the confidentiality, integrity, and availability of the system.\nThe impact includes potential full system compromise, remote command execution, data exfiltration, and further lateral movement within the network. Because the vulnerability allows for the direct placement of executable code on the server, the risk is categorized as high. Exploitation does not require advanced user interaction but relies on the application's insufficient file handling logic, effectively bypassing security controls meant to sanitize user-supplied content.",
"technicalDetails": "The vulnerability is classified as an Unrestricted Upload of File with Dangerous Type (CWE-434). It stems from the application's insufficient validation mechanisms regarding the 'Content-Type' header or file extensions of uploaded artifacts. In versions 1.7.7 and earlier, the Zombify upload functionality lacks rigorous server-side checks to distinguish between benign user-supplied content and executable scripts.\nThe attack flow commences with an attacker identifying an upload endpoint within the Zombify application. Since the application fails to verify the file's binary signature (magic bytes) or enforce an allowlist of permitted extensions (e.g., prohibiting .php, .phtml, .asp, or .jsp files), the attacker can bypass security filters by uploading a malicious script disguised as a different file type or by simply ignoring client-side restrictions.\nOnce the file is uploaded, the web server stores it within a directory accessible to the web environment. Because the server is configured to parse scripts, the attacker can then trigger the execution of the web shell by navigating to the file's URL path. The web server interprets the uploaded script, granting the attacker arbitrary command execution privileges consistent with the service account running the web application (e.g., www-data).\nPost-exploitation activities are highly flexible. An attacker who successfully achieves code execution can interact with the server's filesystem, modify source code, intercept sensitive traffic, or pivot into the internal network. The ability to upload arbitrary files provides a persistent backdoor, as the attacker can re-access the shell at any time after the initial entry, provided the file is not periodically cleaned or monitored by security tooling. This vulnerability essentially turns a standard web application feature into a remote access gateway for unauthorized actors."
}