CVE-2026-75496
HIGH
NVD
CVSS Score
7.2
Severity
HIGH
Published
Aug 25, 2026
Vendor
unknown
Description
Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.