#VU124768 PHP file inclusion in Emlog Pro - CVE-2026-34787

 

#VU124768 PHP file inclusion in Emlog Pro - CVE-2026-34787

Published: April 1, 2026


Vulnerability identifier: #VU124768
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2026-34787
CWE-ID: CWE-98
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
Emlog Pro
Software vendor:
Emlog

Description

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to the local file inclusion (LFI) issue in admin/plugin.php. A remote administrator can send a specially crafted HTTP request to the affected application, include and execute arbitrary PHP code on the system with privileges of the web server.


Remediation

Install updates from vendor's website.

External links