CVE Watchtower


← Back to CVE List

CVE-2026-39276NVD

Vulnerability Summary

The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default template files or directly include malicious code files in the current template.
Severity Level
HIGH(7.2)
Published Date
May 29, 2026
Last Modified
Jun 1, 2026
Exploitation Status
UNKNOWN
Root Weakness (CWE)
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.
EPSS Score (30-Day)
0.23%Probability
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh