CVE-2026-39276

The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default template files or directly include malicious code files in the current template.
References
Link Resource
https://github.com/LING12138-sg/Emlog-v2.6.9-Vulnerability-Report Exploit Mitigation Third Party Advisory
https://www.emlog.net/ Product
https://github.com/LING12138-sg/Emlog-v2.6.9-Vulnerability-Report Exploit Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:emlog:emlog:2.6.9:*:*:*:pro:*:*:*

History

No history.

Information

Published : 2026-05-29 16:16

Updated : 2026-07-21 15:10


NVD link : CVE-2026-39276

Mitre link : CVE-2026-39276

CVE.ORG link : CVE-2026-39276


JSON object : View

Products Affected

emlog

  • emlog
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')