PT-2026-2311 · Emlog · Emlog

Hebing123

·

Published

2026-01-12

·

Updated

2026-01-21

·

CVE-2026-22799

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Emlog versions prior to 2.6.1
Description Emlog is a website building system. Versions prior to 2.6.1 expose a REST API endpoint ('/index.php?rest-api=upload') for media file uploads. This endpoint does not properly validate file types, extensions, or content, allowing authenticated attackers with a valid API key or admin session cookie to upload arbitrary files, including malicious PHP scripts. Once uploaded, these files can be executed, potentially leading to remote code execution (RCE) and full server compromise. Attackers can obtain the API key by gaining administrator access or through information disclosure vulnerabilities within the application.
Recommendations Versions prior to 2.6.1 should be updated to version 2.6.1 or later.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-22799
GHSA-P837-MRW9-5X5J

Affected Products

Emlog