PT-2026-30256 · Emlog · Emlog

·

CVE-2026-34228

·

Published

2026-04-03

·

Updated

2026-07-24

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Emlog versions prior to 2.6.8
Description The backend upgrade interface allows the submission of remote SQL and ZIP URLs through GET parameters. The server downloads and executes the SQL file and extracts the ZIP file directly into the web root directory without validating a CSRF (Cross-Site Request Forgery) token—a mechanism used to prevent unauthorized commands from being transmitted from a user that the web application trusts. This allows an attacker to trick an authenticated administrator into visiting a malicious link, resulting in arbitrary SQL execution and arbitrary file write.
Recommendations Update to version 2.6.8.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34228
GHSA-2RCC-JG83-34VP

Affected Products

Emlog