Authorization bypass through user-controlled key in REDAXO - #VU140848
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to modify arbitrary media files by moving them into a permitted category.
The vulnerability exists due to missing authorization in the media pool bulk move operation when processing selected files for category reassignment. A remote user can select files from categories they are not permitted to control and move them into a category they control to modify arbitrary media files by replacing their contents.
The issue affects authenticated backend sessions and does not require a crafted request or victim interaction.