Xerte Online Toolkits <= 3.15 - Remote Code Execution
CVE-2026-34413
Verified
Description
Xerte Online Toolkits versions 3.15 and earlier expose the elFinder file manager connector at /editor/elfinder/php/connector.php without authentication (CVE-2026-34413), because the access-control redirect for unauthenticated users does not call exit()/die() and execution continues server-side. This is chained with a relative path traversal in the elFinder rename command (CVE-2026-34414) and an incomplete file-extension blocklist that still permits .php4 (CVE-2026-34415) to write an attacker-controlled PHP file into the application root, resulting in unauthenticated remote code execution.
Severity
Critical
CVSS Score
9.8
Exploit Probability
3%
Affected Product
xerte_online_toolkits
Published Date
June 21, 2026
Template Author
aryu-ru
CVE-2026-34413.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-34413
CWE ID:
cwe-306
References
https://www.vulncheck.com/advisories/xerte-online-toolkits-missing-authentication-via-connector-phphttps://github.com/bootstrapbool/xerteonlinetoolkits-rcehttps://github.com/thexerteproject/xerteonlinetoolkits/issues/1527https://nvd.nist.gov/vuln/detail/CVE-2026-34413https://nvd.nist.gov/vuln/detail/CVE-2026-34414https://nvd.nist.gov/vuln/detail/CVE-2026-34415
Remediation Steps
Update to a fixed release. The fix, which adds exit() after the access-control redirect and sanitizes elFinder file names, was backported to the 3.13, 3.14 and 3.15 branches.