PT-2026-6065 · Bolo Blog+1 · Bolo-Blog+1

·

CVE-2026-1813

·

Published

2026-02-03

·

Updated

2026-03-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bolo-blog bolo-solo versions up to 2.6.4
Description A flaw exists in bolo-blog bolo-solo up to version 2.6.4, specifically within the FreeMarker Template Handler component and the file src/main/java/org/b3log/solo/bolo/pic/PicUploadProcessor.java. The issue involves unrestricted file upload, potentially triggered by manipulating the File argument. This allows for remote exploitation. The exploit for this issue has been publicly released. The project maintainers were notified of the problem but have not yet responded.
Recommendations Versions up to 2.6.4 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1813

Affected Products

Bolo-Blog
Bolo-Solo