CVE-2026-39276

The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default template files or directly include malicious code files in the current template.
References
Link Resource
https://github.com/LING12138-sg/Emlog-v2.6.9-Vulnerability-Report Exploit Mitigation Third Party Advisory
https://www.emlog.net/ Product
https://github.com/LING12138-sg/Emlog-v2.6.9-Vulnerability-Report Exploit Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:emlog:emlog:2.6.9:*:*:*:pro:*:*:*

History

11 Jun 2026, 18:32

Type Values Removed Values Added
References () https://github.com/LING12138-sg/Emlog-v2.6.9-Vulnerability-Report - () https://github.com/LING12138-sg/Emlog-v2.6.9-Vulnerability-Report - Exploit, Mitigation, Third Party Advisory
References () https://www.emlog.net/ - () https://www.emlog.net/ - Product
CPE cpe:2.3:a:emlog:emlog:2.6.9:*:*:*:pro:*:*:*
First Time Emlog
Emlog emlog

29 May 2026, 20:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
CWE CWE-22
References () https://github.com/LING12138-sg/Emlog-v2.6.9-Vulnerability-Report - () https://github.com/LING12138-sg/Emlog-v2.6.9-Vulnerability-Report -

29 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 16:16

Updated : 2026-06-11 18:32


NVD link : CVE-2026-39276

Mitre link : CVE-2026-39276

CVE.ORG link : CVE-2026-39276


JSON object : View

Products Affected

emlog

  • emlog
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')