Path traversal in baserCMS - CVE-2026-62955

 

Path traversal in baserCMS - CVE-2026-62955

Published: July 30, 2026


Vulnerability identifier: #VU140530
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62955
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to path traversal in BcThemeFileService::getFullpath() when handling a type value that maps to a non-existent theme subdirectory. A remote privileged user can supply a crafted path containing traversal sequences to execute arbitrary code.

The issue occurs because the directory traversal validation is skipped when realpath() returns false for the base directory, and exploitation can be used to write files outside the intended theme directory.


Affected software

baserCMS

How to mitigate CVE-2026-62955

Install security update from vendor's website.

baserCMS - update to 5.3.0

External References

Related Security Bulletins