CVE-2026-2334
vsDesk
An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.
- CVSS
- 9.4
- EPSS
- 0.52% 42.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.21