Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
CVE coverage

CVE-2026-103474

CVSS 8.8 no coverage
View on NVD →
yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.

Detection rules

No detection found — yet
None of Sigma, Elastic, Splunk ESCU, YARA, Microsoft Sentinel, Snort, or Suricata currently has a rule referencing CVE-2026-103474.