CVE-2026-16219

MEDIUM LAB

Croogo CMS Admin File Manager FileManager.php isEditable path traversal

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-16219. PoCs published by HELLBOY3110.

AI-analyzed exploit summary This repository provides a proof-of-concept exploit for CVE-2026-16219, a path authorization bypass vulnerability in Croogo CMS. The exploit demonstrates how improper path validation in the FileManager component allows authenticated users to write files outside configured editable paths by leveraging a type confusion flaw in `Configure::check()` vs `Configure::read()`.

Description

A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager::isEditable of the file FileManager/src/Utility/FileManager.php of the component Admin File Manager. This manipulation causes path traversal. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Exploits (1)

github WORKING POC
by HELLBOY3110 · shellpoc
https://github.com/HELLBOY3110/cve-2026-16219-croogo-lab

This repository provides a proof-of-concept exploit for CVE-2026-16219, a path authorization bypass vulnerability in Croogo CMS. The exploit demonstrates how improper path validation in the FileManager component allows authenticated users to write files outside configured editable paths by leveraging a type confusion flaw in `Configure::check()` vs `Configure::read()`.

Classification
Working Poc 99%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Croogo CMS (FileManager component, versions affected by CVE-2026-16219)
Auth required
Prerequisites: Authenticated access to Croogo CMS with CSRF token · Target must be running on a system where `/tmp` is writable · Attacker must control a loopback (127.0.0.1) instance of Croogo
mistral-large-3 · analyzed Jul 20, 2026 Full analysis →

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-380042 | Croogo CMS Admin File Manager FileManager.php isEditable path traversal
https://vuldb.com/vuln/380042
Signature, Permissions Required signature permissions-required
VDB-380042 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/380042/cti
Third Party Advisory third-party-advisory
CVE-2026-16219 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-16219
Third Party Advisory third-party-advisory
Submit #857986 | Croogo fc0648659dcb5790ba8a7429250dae492ca724ec Arbitrary File Write / Path Traversal
https://vuldb.com/submit/857986
Issue Tracking issue-tracking
https://github.com/croogo/croogo/issues/1008

Scores

CVSS v3 6.3
EPSS 0.0034
EPSS Percentile 26.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Lab Environment

COMMUNITY
Community Lab
docker pull eclipse-temurin:17-jdk
docker pull gcr.io/oss-fuzz-base/base-builder

Details

CWE
CWE-22
Status published
Products (8)
Croogo/CMS 4.0.0
Croogo/CMS 4.0.1
Croogo/CMS 4.0.2
Croogo/CMS 4.0.3
Croogo/CMS 4.0.4
Croogo/CMS 4.0.5
Croogo/CMS 4.0.6
Croogo/CMS 4.0.7
Published Jul 19, 2026
Tracked Since Jul 19, 2026