Sceawere

Vulnerability Detail

CVE-2026-94503UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zombify Unrestricted File Upload Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
3h ago
Vendor
PX-lab
Product
Zombify
Attack Type
Unrestricted Upload of File with Dangerous Type
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-10-09T10:16:40.607Z",
  "pubdate": "2026-10-09T10:16:40.607Z",
  "executiveSummary": "The Zombify application, developed by PX-lab, is susceptible to an Unrestricted Upload of File with Dangerous Type vulnerability. This flaw exists in all versions from n/a through 1.7.7.\nThe vulnerability originates from the application's failure to adequately validate or restrict the file types permitted during the upload process. An attacker can exploit this by uploading malicious files, such as web shells, directly to the web server.\nSuccessful exploitation grants an unauthorized attacker the ability to execute arbitrary code within the context of the web server process. This poses a critical risk to the confidentiality, integrity, and availability of the system.\nThe impact includes potential full system compromise, remote command execution, data exfiltration, and further lateral movement within the network. Because the vulnerability allows for the direct placement of executable code on the server, the risk is categorized as high. Exploitation does not require advanced user interaction but relies on the application's insufficient file handling logic, effectively bypassing security controls meant to sanitize user-supplied content.",
  "technicalDetails": "The vulnerability is classified as an Unrestricted Upload of File with Dangerous Type (CWE-434). It stems from the application's insufficient validation mechanisms regarding the 'Content-Type' header or file extensions of uploaded artifacts. In versions 1.7.7 and earlier, the Zombify upload functionality lacks rigorous server-side checks to distinguish between benign user-supplied content and executable scripts.\nThe attack flow commences with an attacker identifying an upload endpoint within the Zombify application. Since the application fails to verify the file's binary signature (magic bytes) or enforce an allowlist of permitted extensions (e.g., prohibiting .php, .phtml, .asp, or .jsp files), the attacker can bypass security filters by uploading a malicious script disguised as a different file type or by simply ignoring client-side restrictions.\nOnce the file is uploaded, the web server stores it within a directory accessible to the web environment. Because the server is configured to parse scripts, the attacker can then trigger the execution of the web shell by navigating to the file's URL path. The web server interprets the uploaded script, granting the attacker arbitrary command execution privileges consistent with the service account running the web application (e.g., www-data).\nPost-exploitation activities are highly flexible. An attacker who successfully achieves code execution can interact with the server's filesystem, modify source code, intercept sensitive traffic, or pivot into the internal network. The ability to upload arbitrary files provides a persistent backdoor, as the attacker can re-access the shell at any time after the initial entry, provided the file is not periodically cleaned or monitored by security tooling. This vulnerability essentially turns a standard web application feature into a remote access gateway for unauthorized actors."
}
CVE-2026-94503: Zombify Unrestricted File Upload Vulnerability (CRITICAL Severity, CVSS: 10.0) | Sceawere