Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-2334: vsDesk lets admin run code through CSV import

CVE-2026-2334 · published 1 month ago
Summary

In vsDesk version 14.0101, an admin user can bypass the file checks when using the CSV import feature and upload any file. This can let the attacker execute code on the server through the web application. Update to version 14.0402 or later from the vendor’s website to fix the issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
vsdesk vsdesk 14.0101
Original advisory text
An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server...
An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application. 
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.
Severity
9.4 Critical
CVSS 4.0: 9.4 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published20 Aug 2026
Updated27 Sep 2026
First seen20 Aug 2026
Sources
CVE-2026-2334 · NVD
CVE-2026-2334 · MITRE
Track software like this
Free during beta