Medium severity4.8NVD Advisory· Published Aug 8, 2023· Updated Jun 17, 2026
CVE-2023-26961
CVE-2023-26961
Description
Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attackers to upload arbitrary files (e.g., JavaScript content for stored XSS) via the type field in a JSON document within a PUT /gallery/api/media request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Alteryx/Serverdescription
- Range: 2022.1.1.42590
Patches
Vulnerability mechanics
References
2- gist.github.com/DylanGrl/4269ae834c5d0ec77c9b928ad35d3be3nvdExploitThird Party Advisory
- alteryx.comnvdVendor Advisory
News mentions
0No linked articles in our index yet.