CIVI-SA-2026-01: File API - Remote Code Execution

Publié
2026-03-18 12:00
Written by

A user with permission to manage File uploads via APIv4 can escalate to executing arbitrary PHP files.

Security Risk
Critical
Vulnerability
Arbitrary PHP Code Execution
Affected Versions

CiviCRM v6.2.0 - 6.12.0

Fixed Versions

CiviCRM v6.12.1, v6.10.3 (ESR), and later

Publication Date
Solutions

Any ONE of the following will mitigate the vulnerability:

  • Upgrade to a fixed version of CiviCRM, or...
  • Revoke the permission access uploaded files from non-administrators
Credits

Lassi (lassitemp@proton.me), Coleman Watts (CiviCRM), Tim Otten (CiviCRM), Seamus Lee (JMA Consulting)