Home

Description

Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The application does not adequately restrict uploaded file types, allowing malicious files to be uploaded and executed by the server. This condition enables remote code execution under default configurations.

PUBLISHED Reserved 2025-08-19 | Published 2026-01-28 | Updated 2026-01-28 | Assigner Mandiant

Problem types

CWE-434 Unrestricted Upload of File with Dangerous Type

Product status

Default status
unaffected

Any version before 8.14.9
affected

Credits

Abdulrahman Nour, Mandiant finder

Abdulrahman Nour, Mandiant reporter

References

www.explorance.com/products/blue product

online-help.explorance.com/...rity-advisories-(january-2026) vendor-advisory

online-help.explorance.com/...urity-advisory:-cve-2025-57794 vendor-advisory

github.com/...Disclosures/blob/master/2026/MNDT-2026-0003.md third-party-advisory

cve.org (CVE-2025-57794)

nvd.nist.gov (CVE-2025-57794)

Download JSON