MindsDB - Remote Code Execution
CVE-2026-27483
Verified
Description
MindsDB < 25.9.1.1 contains a remote code execution caused by path traversal in the /api/files upload file module, letting authenticated attackers write arbitrary files and execute commands, exploit requires authentication.
Severity
High
CVSS Score
8.8
Exploit Probability
9%
Affected Product
MindsDB
Published Date
March 6, 2026
Template Author
thewhiteh4t
CVE-2026-27483.yaml
8.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-27483
CWE ID:
cwe-22
Remediation Steps
Upgrade to version 25.9.1.1 or later.