{"id":"CVE-2026-2334","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-2334","summary":"An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the \"Import via CSV\" component due to…","details":"An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the \"Import via CSV\" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application. \nApply patch from vendor  https://vsdesk.ru/ . Versions 14.0402 and on have the patch.","published":"2026-08-20T18:16:26.047","modified":"2026-08-21T21:16:56.610","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/klsecservices/Advisories/blob/master/KLSA-00415-Missing-Server-Side-File-Extension-Validation-in-vsDesk.md"},{"type":"WEB","url":"https://vsdesk.ru/news/vyshla-novaya-versiya-140422"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-21T21:16:56.610"}}