Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

F3Nrir77

#24645of 55,078
9.9Total CVSS
Vulnerabilities · 1
PT-2026-44820
9.9
2026-05-29
Mautic · Mautic · CVE-2026-9559
**Name of the Vulnerable Software and Affected Versions** Mautic versions 7.0.0 through 7.1.1 **Description** A path traversal flaw exists in the campaign import feature. During the extraction of uploaded ZIP files, a validation error allows file paths to exit the designated temporary directories. An authenticated user with `campaign:imports:create` privileges can write arbitrary PHP files to sensitive system directories, potentially overwriting internal configuration or cache components. This can lead to Remote Code Execution (RCE), which is the ability to execute arbitrary commands on a remote machine, under the context of the web server user. **Recommendations** Update to version 7.1.2. Revoke `campaign:imports:create` permissions from non-administrative users.