CVE-2026-39276

HIGH

Emlog Pro 2.6.9 - Authenticated Path Traversal and Arbitrary PHP Code Execution via Template Upload

Title source: llm
STIX 2.1

Description

The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default template files or directly include malicious code files in the current template.

Scores

CVSS v3 7.2
EPSS 0.0068
EPSS Percentile 47.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
emlog/emlog 2.6.9
Published May 29, 2026
Tracked Since May 29, 2026