A vulnerability was determined in ZenTao up to 21.7.8. Affected by this vulnerability is the function delete of the file editor/control.php of the component Backup Handler. This manipulation of the argument fileName causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
References
| Link | Resource |
|---|---|
| https://github.com/ez-lbz/ez-lbz.github.io/issues/10 | Exploit Issue Tracking |
| https://vuldb.com/?ctiid.346160 | Permissions Required VDB Entry |
| https://vuldb.com/?id.346160 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.749983 | Third Party Advisory VDB Entry |
Configurations
History
20 Feb 2026, 19:06
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/ez-lbz/ez-lbz.github.io/issues/10 - Exploit, Issue Tracking | |
| References | () https://vuldb.com/?ctiid.346160 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.346160 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.749983 - Third Party Advisory, VDB Entry | |
| CPE | cpe:2.3:a:zentao:zentao:*:*:*:*:*:*:*:* | |
| First Time |
Zentao
Zentao zentao |
18 Feb 2026, 17:52
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
16 Feb 2026, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-16 11:15
Updated : 2026-02-20 19:06
NVD link : CVE-2026-2551
Mitre link : CVE-2026-2551
CVE.ORG link : CVE-2026-2551
JSON object : View
Products Affected
zentao
- zentao
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
