CVE-2026-58428
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Related CWEs
CWE-424
Improper Protection of Alternate Path
The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.
CWE-434
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
References (4)
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Timeline
No history available yet.