PT-2026-28728 · Elecv2 · Elecv2

Zast.Ai

·

Published

2026-03-28

·

Updated

2026-03-29

·

CVE-2026-5014

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions elecV2 versions prior to 3.8.4
Description A path traversal issue exists due to the manipulation of the path.join function within the /log/ file of the Wildcard Handler component. This allows for remote exploitation. The project was notified of the issue but has not yet responded. The exploit has been publicly disclosed.
Recommendations Update to version 3.8.4 or later. As a temporary workaround, restrict access to the /log/ file. Consider disabling the Wildcard Handler component until a patch is available.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-5014

Affected Products

Elecv2