HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-25099 — Bludit’s API plugin allows an authenticated attacker with a valid API token to u...

Friday, March 27, 2026 at 12:16 PM UTC·Source: NIST NVD

Updated: Thursday, April 2, 2026 at 05:46 PM UTC

Executive Summary

Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.

Analysis

Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4. CVSS Score: 8.8. Published: 2026-03-27T12:16:19.007.

Indicators of Compromise (1)

CVE (1)
CVE-2026-25099
Source Attribution

Originally published by NIST NVD on Mar 27, 2026. Verified by: NIST.

Related Threats