CVE-2026-56394

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowing local file read access.
Configurations

No configuration.

History

21 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-21 14:16

Updated : 2026-06-23 14:17


NVD link : CVE-2026-56394

Mitre link : CVE-2026-56394

CVE.ORG link : CVE-2026-56394


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')