Path traversal in Emlog Pro - CVE-2026-53757

 

Path traversal in Emlog Pro - CVE-2026-53757

Published: August 15, 2026


Vulnerability identifier: #VU142815
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53757
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to path traversal in the emUnZip() ZIP extraction function when processing uploaded plugin or template ZIP archives. A remote user can upload a specially crafted ZIP archive containing traversal entries to execute arbitrary code.

Exploitation requires access to the administrative plugin, template upload, or store update functionality, and exploitation was confirmed on PHP 7.x and early PHP 8.0.x releases.


Affected software

Emlog Pro

How to mitigate CVE-2026-53757

Install security update from vendor's website.

Emlog Pro - update to 2.6.17

External References

Related Security Bulletins