PHP file inclusion in Emlog Pro - CVE-2026-34787

 

PHP file inclusion in Emlog Pro - CVE-2026-34787

Published: April 1, 2026


Vulnerability identifier: #VU124768
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34787
CWE-ID: CWE-98
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to the local file inclusion (LFI) issue in admin/plugin.php. A remote administrator can send a specially crafted HTTP request to the affected application, include and execute arbitrary PHP code on the system with privileges of the web server.


Affected software

Emlog Pro

How to mitigate CVE-2026-34787

Install updates from vendor's website.

Emlog Pro - update to 2.6.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins