CVE-2026-40521
HIGHFrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
Title source: cnaDescription
FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authenticated attackers to execute arbitrary code by uploading files with traversal sequences in the unique_name parameter. Attackers can supply path traversal sequences ../../../shell.php to write files outside the intended attachments directory into the web root, and by uploading PHP files without extension validation, achieve remote code execution as the web server user.
References (4)
Core 4
Core References
Exploit technical-description
exploit
https://jivasecurity.com/writeups/frontaccounting-rce-attachment-upload-cve-2026-40521
Release Notes release-notes
https://sourceforge.net/p/frontaccounting/news/2026/04/release-2420/
Patch patch
https://github.com/FrontAccountingERP/FA/commit/701fea6848da4a02fb83d30f07a9c0473d6b7e33
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/frontaccounting-path-traversal-rce-via-attachment-upload
Scores
CVSS v3
8.8
EPSS
0.0063
EPSS Percentile
46.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (2)
FrontAccounting/FrontAccounting
< 2.4.20
FrontAccounting/FrontAccounting
701fea6848da4a02fb83d30f07a9c0473d6b7e33
Published
Jun 29, 2026
Tracked Since
Jun 29, 2026