LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-48939: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 10, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 13, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-48939 to its Known Exploited Vulnerabilities catalog on Jul 10, 2026, with a federal patch deadline of Jul 13, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and…

This vulnerability affects the iCagenda component and stems from an unrestricted file upload weakness in its attachment feature. Attackers can submit files of dangerous types that the application does not properly validate, resulting in the placement and execution of PHP code on the server.

How it works

The flaw is categorized as CWE-434, unrestricted upload of file with dangerous type. In this class of weakness the application accepts user-supplied files without sufficiently restricting their content type, extension, or destination. An attacker supplies a file through the attachment mechanism; because no effective server-side controls block executable content, the file is stored in a web-accessible location and can later be requested to run server-side code.

Am I affected? How to find it in your systems

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation. After patching, review and tighten file-upload controls for the attachment feature: enforce an allow-list of permitted MIME types and extensions, store uploaded files outside the web root, and rename files on receipt so that executable extensions are never preserved.

If you can't patch immediately

If your data may have been exposed

Active exploitation of upload vulnerabilities has led to unauthorized access and data exposure in other environments. Organizations can run a free exposure scan of their email addresses against known breach data to determine whether related credentials or information have already appeared in public records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectediCagenda · iCagenda
WeaknessCWE-434
Added to CISA KEVJul 10, 2026
Federal patch deadlineJul 13, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities