CVE-2026-22102EPSS p42.9%
CVE-2026-22102CVE-2026-22102
Description
A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in the Content-Disposition header without verification.
This can be used to cause a denial of service by overwriting system files, or remote-code-execution by overwriting shell-scripts which execution can be triggered through other means.
Scoring
| EPSS | 0.53% probability of exploitation · percentile 42.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-13 |