THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-98pp-vccm-qm25 (high) — Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers

[GHSA] GHSA-98pp-vccm-qm25 (high) — Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers

highgithub_advisoriesPublished 2026-07-31

GHSA-98pp-vccm-qm25 Severity: high CVE: CVE-2026-53599

Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers

## Summary

`rex_mediapool::isAllowedExtension` in `redaxo/src/addons/mediapool/lib/mediapool.php` accepts filenames that contain a blocked extension as a non-terminal segment of a longer ext

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-98pp-vccm-qm25