A vulnerability labeled as critical has been found in Studio-42 elFinder up to 2.1.69. This issue affects the function checkExtractItems of the file php/elFinderVolumeDriver.class.php. Executing a manipulation can lead to unrestricted upload. This vulnerability is handled as CVE-2026-81891. The attack can be executed remotely. There is not any exploit available. The affected component should be
PHP
Exploit
CVE-2026-81891
VulDB
Apply vendor security patch