LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-40040

CVE-2026-40040 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: April 13, 2026

Pachno - Unrestricted File Upload

Published: April 13, 2026Updated: April 13, 2026Remote Exploitable

Overview

Pachno 1.0.6 contains an unrestricted file upload vulnerability caused by ineffective extension filtering in the /uploadfile endpoint, letting authenticated users upload and execute arbitrary files, exploit requires authentication.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Authenticated attackers can upload and execute arbitrary files, leading to remote code execution on the server.

Mitigation

Update to the latest version with fixed extension filtering.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 13, 2026

🟠 CVE-2026-40040 - High (8.8) Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint. Attackers can upload executable files .php5 sc... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-40040/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 13, 2026

🟠 CVE-2026-40040 - High (8.8) Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint. Attackers can upload executable files .php5 sc... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-40040/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-40040
Severity
High
CVSS Score
8.8
Type
unrestricted_file_upload
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-434

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days