A vulnerability described as problematic has been identified in Elgg up to 6.3.4/6.x. Affected by this issue is some unknown functionality of the component Avatar Upload. Such manipulation leads to denial of service.

This vulnerability is traded as CVE-2026-65650. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is recommended.