/Vulnerability Library

Xerte Online Toolkits <= 3.15 - Remote Code Execution

CVE-2026-34413
Verified

Description

Xerte Online Toolkits versions 3.15 and earlier expose the elFinder file manager connector at /editor/elfinder/php/connector.php without authentication (CVE-2026-34413), because the access-control redirect for unauthenticated users does not call exit()/die() and execution continues server-side. This is chained with a relative path traversal in the elFinder rename command (CVE-2026-34414) and an incomplete file-extension blocklist that still permits .php4 (CVE-2026-34415) to write an attacker-controlled PHP file into the application root, resulting in unauthenticated remote code execution.

Severity

Critical

CVSS Score

9.8

Exploit Probability

3%

Affected Product

xerte_online_toolkits

Published Date

June 21, 2026

Template Author

aryu-ru

CVE-2026-34413.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-34413
CWE ID:
cwe-306

References

https://www.vulncheck.com/advisories/xerte-online-toolkits-missing-authentication-via-connector-phphttps://github.com/bootstrapbool/xerteonlinetoolkits-rcehttps://github.com/thexerteproject/xerteonlinetoolkits/issues/1527https://nvd.nist.gov/vuln/detail/CVE-2026-34413https://nvd.nist.gov/vuln/detail/CVE-2026-34414https://nvd.nist.gov/vuln/detail/CVE-2026-34415

Remediation Steps

Update to a fixed release. The fix, which adds exit() after the access-control redirect and sanitizes elFinder file names, was backported to the 3.13, 3.14 and 3.15 branches.