CVE-2026-42879 affects FacturaScripts 2025.81 and earlier. The vulnerability is an authenticated unrestricted file upload flaw in the product image upload feature. According to the provided content, the issue resides in addImageAction() in Core/Lib/ExtendedController/ProductImagesTrait.php. An authenticated user can upload a PHP script disguised as a GIF image by prepending a GIF89a header, bypassing MIME-type validation. Because the application stores the uploaded file using the original client-supplied extension, including executable extensions such as .php, the attacker can place executable server-side code in a web-accessible location. On servers configured to execute uploaded PHP files, this can result in remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit for CVE-2026-42879 affecting FacturaScripts. It contains one primary code file, Exploit.py, plus a README, license, and .gitignore. The exploit is not part of a larger framework. Exploit.py implements a fully automated authenticated file-upload-to-RCE chain against FacturaScripts product image handling. The workflow is: authenticate to /login using supplied or default admin/admin credentials; scrape the multireqtoken CSRF token; enumerate products via /ListProducto; open /EditProducto?code=... to extract idproducto and another multireqtoken; generate a local PHP payload prefixed with GIF89a to bypass MIME checks; upload it through the add-image action as newfiles[]; then probe predictable storage paths under /MyFiles/YYYY/MM/1.php through /9.php until the uploaded shell is found. Once located, the script executes commands by sending GET requests with ?cmd=... and drops into an interactive shell. The main capability is authenticated remote code execution via unrestricted file upload and predictable web-accessible storage. The payload is a simple PHP web shell using system($_GET['cmd']). The exploit includes basic automation and fallback assumptions: if product enumeration fails it uses product code CONTA621, and if product ID extraction fails it uses idproducto 3. Success detection relies on the response containing strings such as Dashboard after login, images added correctly after upload, and SHELL_UPLOADED! when probing the shell. The README documents the vulnerability as an authenticated unrestricted file upload in FacturaScripts' ProductImagesTrait::addImageAction(), caused by trusting MIME type checks and preserving the original filename/extension. It states affected versions are FacturaScripts <= 2025.81 and describes the resulting storage path /MyFiles/YYYY/MM/X.php. Overall, this is a real operational exploit with a hardcoded but functional payload, intended to obtain command execution on vulnerable FacturaScripts deployments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.