CVE-2026-48768 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
June 18, 2026
Last Seen
June 18, 2026

CVE-2026-48768 is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 2 intelligence report mentions.

CVE-2026-48768 is a vulnerability tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed June 18, 2026; most recent activity June 18, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • CVE-2026-48768 CVE Vulnerability Disclosures / 14h TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to construct public/ S3 object keys, while issuing presigned PUT URLs that do not bind Content-Type. As a result, any anonymous visitor to a published bot with a file input can upload attacker-controlled HTML, SVG, or JS to attacker-chosen subpaths, including other tenants’ p — cve.report · June 18, 2026
  • CVE-2026-48768 AKAOMA CVE VULNERABILITIES / 14h TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to construct public/ S3 object keys, while issuing presigned PUT URLs that do not bind Content-Type. As a result, any anonymous visitor to a published bot with a file input can upload attacker-controlled HTML, SVG, or JS to attacker-chosen subpaths, including other tenants’ publ — cve.akaoma.com · June 18, 2026

Frequently asked questions

What is CVE-2026-48768?

CVE-2026-48768 is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 2 intelligence report mentions.

Is CVE-2026-48768 still active?

The most recent intelligence report mentioning CVE-2026-48768 on ThreatCluster is dated June 18, 2026.

What is CVE-2026-48768 associated with?

Across ThreatCluster reporting, CVE-2026-48768 most frequently co-occurs with Zero-day Exploit, CWE-22 - Path Traversal, Cwe-79 - Cross-site Scripting (xss), TypeBot, XSS.

What are the latest developments involving CVE-2026-48768?

The most significant recent cluster is “Critical CVE-2026-48768 Vulnerability in TypeBot Exposes Users to File Upload Attacks” (2 articles · Updated June 18, 2026). CVE-2026-48768 appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on CVE-2026-48768?

CVE-2026-48768 appears in 2 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown