轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202607-00000006
[內容說明]
【CVE-2026-48908】JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability (CVSS v3.1: 9.8)
【是否遭勒索軟體利用:未知】 JoomShaper SP Page Builder 存在未受限制的危險類型檔案上傳漏洞,允許未經身分驗證的使用者上傳任意檔案,最終可導致 PHP 程式碼被上傳並執行。
【CVE-2026-55255】Langflow Authorization Bypass Through User-Controlled Key Vulnerability (CVSS v3.1: 8.4)
【是否遭勒索軟體利用:未知】 Langflow 存在身分驗證繞過漏洞,允許已通過身分驗證的攻擊者在請求中指定受害者的工作流程ID,進而執行任何屬於其他使用者的流程。
【CVE-2026-56290】Joomlack Page Builder Improper Access Control Vulnerability (CVSS v3.1: 9.8)
【是否遭勒索軟體利用:未知】 Joomlack Page Builder 存在不當存取控制漏洞,可能允許攻擊者透過未經身分驗證的任意檔案上傳實現遠端程式碼執行。
【CVE-2026-48282】Adobe ColdFusion Path Traversal Vulnerability (CVSS v3.1: 10.0)
【是否遭勒索軟體利用:未知】 Adobe ColdFusion 存在路徑遍歷漏洞,可能導致在當前使用者權限下執行任意程式碼。
【CVE-2026-56291】Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability (CVSS v3.1: 9.8)
【是否遭勒索軟體利用:未知】 Balbooa Forms 存在未受限制的危險類型檔案上傳漏洞,允許未經身分驗證的任意檔案上傳,進而導致遠端程式碼執行。
【CVE-2026-48939】iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability (CVSS v3.1: 9.8)
【是否遭勒索軟體利用:未知】 iCagenda 存在未受限制的危險類型檔案上傳漏洞,攻擊者可利用檔案附件功能上傳任意檔案,最終導致 PHP 程式碼被上傳並執行。
[影響平台]
【CVE-2026-48908】請參考所列影響版本 https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/
【CVE-2026-55255】請參考官方所列的影響版本 https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2
【CVE-2026-56290】請參考所列影響版本 https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/
【CVE-2026-48282】請參考官方所列的影響版本 https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
【CVE-2026-56291】請參考所列影響版本 https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/
【CVE-2026-48939】請參考所列影響版本 https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/
[建議措施]
【CVE-2026-48908】 已針對漏洞釋出修復更新,請更新至相關版本 https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/
【CVE-2026-55255】 官方已針對漏洞釋出修復更新,請更新至相關版本 https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2
【CVE-2026-56290】 已針對漏洞釋出修復更新,請更新至相關版本 https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/
【CVE-2026-48282】 官方已針對漏洞釋出修復更新,請更新至相關版本 https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
【CVE-2026-56291】 已針對漏洞釋出修復更新,請更新至相關版本 https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/
【CVE-2026-48939】 已針對漏洞釋出修復更新,請更新至相關版本 https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/
Forwarded Taiwan Computer Emergency Response Team / Coordination Center Security Advisory Alert TWCERTCC-200-202607-00000006
[Description]
【CVE-2026-48908】JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: unknown】 JoomShaper SP Page Builder has an unrestricted upload of file with dangerous type vulnerability, allowing unauthenticated users to upload arbitrary files, which may ultimately lead to PHP code being uploaded and executed.
【CVE-2026-55255】Langflow Authorization Bypass Through User-Controlled Key Vulnerability (CVSS v3.1: 8.4)
【Whether exploited by ransomware: unknown】 Langflow has an authentication bypass vulnerability, allowing authenticated attackers to specify a victim’s workflow ID in the request and thereby execute any workflows belonging to other users.
【CVE-2026-56290】Joomlack Page Builder Improper Access Control Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: unknown】 Joomlack Page Builder has an improper access control vulnerability, which may allow attackers to achieve remote code execution through unauthenticated arbitrary file upload.
【CVE-2026-48282】Adobe ColdFusion Path Traversal Vulnerability (CVSS v3.1: 10.0)
【Whether exploited by ransomware: unknown】 Adobe ColdFusion has a path traversal vulnerability, which may result in arbitrary code execution under the current user’s privileges.
【CVE-2026-56291】Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: unknown】 Balbooa Forms has an unrestricted upload of file with dangerous type vulnerability, allowing unauthenticated arbitrary file upload, which may lead to remote code execution.
【CVE-2026-48939】iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: unknown】 iCagenda has an unrestricted upload of file with dangerous type vulnerability. Attackers can exploit the file attachment function to upload arbitrary files, ultimately resulting in PHP code being uploaded and executed.
[Affected Platform]
【CVE-2026-48908】Please refer to the listed affected versions https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/
【CVE-2026-55255】Please refer to the affected versions listed by the official https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2
【CVE-2026-56290】Please refer to the listed affected versions https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/
【CVE-2026-48282】Please refer to the affected versions listed by the official https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
【CVE-2026-56291】Please refer to the listed affected versions https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/
【CVE-2026-48939】Please refer to the listed affected versions https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/
[Recommendations]
【CVE-2026-48908】 Fixes have been released for the vulnerability. Please update to the relevant versions https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/
【CVE-2026-55255】 The official has released fixes for the vulnerability. Please update to the relevant versions https://github.com/langflow-ai/langflow/security/advisories/GHSA-qrpv-q767-xqq2
【CVE-2026-56290】 Fixes have been released for the vulnerability. Please update to the relevant versions https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/
【CVE-2026-48282】 The official has released fixes for the vulnerability. Please update to the relevant versions https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
【CVE-2026-56291】 Fixes have been released for the vulnerability. Please update to the relevant versions https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/
【CVE-2026-48939】 Fixes have been released for the vulnerability. Please update to the relevant versions https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/