Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files.