CVE-2026-2334 PUBLISHED

) Missing Server-Side File Extension Validation in vsDesk

Assigner: Kaspersky
Reserved: 11.02.2026 Published: 20.08.2026 Updated: 20.08.2026

An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application.  Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor vsDesk
Product vsDesk
Versions Default: unknown
  • Version 14.0101 is affected
  • Version 14.0402 is unaffected

Credits

  • The vulnerability was discovered by Kirill Nikolaev from Kaspersky (https://kaspersky.com) finder

References

Problem Types

  • CWE-434 Unrestricted upload of file with dangerous type CWE

Impacts

  • CAPEC-207: Removing Important Client Functionality