CVE-2026-53757

Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry paths for ../ traversal sequences. Only the first entry's subdirectory structure is checked. An attacker can overwrite arbitrary files on the server filesystem, including config.php for immediate RCE. At time of publication, there are no publicly known patches.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 18:17

Updated : 2026-09-08 21:05


NVD link : CVE-2026-53757

Mitre link : CVE-2026-53757

CVE.ORG link : CVE-2026-53757


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')