PT-2026-2105 · Redaxo · Backup Addon+1

Lukasz-Rybak

·

Published

2026-01-05

·

Updated

2026-01-20

·

CVE-2026-21857

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions REDAXO versions prior to 5.20.2
Description REDAXO is a PHP-based content management system. Authenticated users with backup permissions can read arbitrary files within the webroot due to a path traversal issue in the Backup addon’s file export functionality. The Backup addon does not validate the EXPDIR POST parameter against a permitted directory allowlist. An attacker can use relative paths containing ../ sequences, or even absolute paths within the document root, to include any readable file in a generated .tar.gz archive. The EXPDIR parameter is vulnerable to path traversal.
Recommendations Versions prior to 5.20.2 should be updated to version 5.20.2 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-21857
GHSA-824X-88XG-CWRV

Affected Products

Backup Addon
Redaxo