Path traversal in NukeViet - CVE-2026-54065

 

Path traversal in NukeViet - CVE-2026-54065

Published: July 24, 2026


Vulnerability identifier: #VU139333
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54065
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete arbitrary files within the application root.

The vulnerability exists due to path traversal in modules/comment/admin/edit.php when processing the attach parameter in HTTP POST requests. A remote privileged user can submit a specially crafted attach parameter to delete arbitrary files within the application root.

The issue is triggered when the edited comment is subsequently deleted, and deleting config.php can render the application inoperable.


Affected software

NukeViet

How to mitigate CVE-2026-54065

Install security update from vendor's website.

NukeViet - update to 4.5.09

External References

Related Security Bulletins