THREAT OPS › Threat News › [GHSA] GHSA-98pp-vccm-qm25 (high) — Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
[GHSA] GHSA-98pp-vccm-qm25 (high) — Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
GHSA-98pp-vccm-qm25 Severity: high CVE: CVE-2026-53599
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
## Summary
`rex_mediapool::isAllowedExtension` in `redaxo/src/addons/mediapool/lib/mediapool.php` accepts filenames that contain a blocked extension as a non-terminal segment of a longer ext
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- 9d008697dcec6bf5a972bdc081fadb68e9dab7fasha1
- CVE-2026-53599cve
Original source: https://github.com/advisories/GHSA-98pp-vccm-qm25