Back Redpacketsecurity CVE Alert: CVE-2026-86305 – light0011
A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Upload::upload of the file ThinkPHP/Library/Think/Upload.class.php. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
High operational urgency: publicly available exploitation and unauthenticated remote reachability make internet-facing deployments a near-term target, although KEV, SSVC and EPSS status are not provided.
An attacker may place executable or otherwise dangerous content on the server, leading to website defacement, malware delivery, data theft or service disruption. The practical impact depends on upload-directory permissions, server-side execution rules and the privileges of the web process; the available scoring indicates confidentiality, integrity and availability consequences are all plausible.
### Most likely attack path
An attacker sends a crafted upload request directly to the exposed web application, requiring no account, user interaction or complex preparation. If uploaded content is stored in a web-accessible, executable location, this could become code execution and provide a foothold for credential theft or further compromise; scope is otherwise assessed as unchanged.
### Who is most exposed
Internet-facing installations, particularly small self-hosted CMS sites, shared hosting environments and administrative portals exposed without an upstream web application firewall, are most at risk. Sites permitting public submissions or poorly segregated media directories warrant immediate review.
Review web logs for unusual multipart upload requests and repeated upload failures.
upload directories for recently created scripts, archives or double-extension filenames.
Alert on web-process child shells, interpreters, or outbound connections.
Check file creation followed by immediate HTTP requests to the same path.
Compare web roots and upload areas against a known-good baseline.
### Mitigation and prioritisation
Apply a vendor fix or known-good commit urgently; patch availability is uncertain.
Disable uploads where unnecessary and block script execution in upload directories.
Enforce allow-listed extensions, MIME validation, renaming and storage outside the web root.
Isolate affected sites and rotate credentials if suspicious files or activity are found.
Confirm KEV, SSVC and EPSS values before final queue placement; current evidence supports expedited change control.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
