RaqibCTI
CVE

CVE-2026-48939

P2
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda · iCagenda
Date added (CISA)
2026-07-10
Remediation due
2026-07-13
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date
Associated with
Related to
  • Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaignCorrelated cluster2026-09-16
  • DysphoriacampaignCorrelated cluster2026-08-24

Description

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Source: NVD ↗ · CISA KEV Catalog ↗