CVE-2026-25099 — Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. — CVE Database · The Intelligence Room