PT-2026-30265 · Emlog · Emlog

·

CVE-2026-34607

·

Published

2026-04-03

·

Updated

2026-07-24

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emlog versions prior to 2.6.2
Description A path traversal issue exists in the emUnZip() function. This occurs during the extraction of ZIP archives, such as when uploading plugins, templates, or importing backups, because the function calls $zip->extractTo($path) without sanitizing ZIP entry names. An authenticated administrator can upload a specially crafted ZIP file containing ../ sequences to write arbitrary files to the server filesystem, which can lead to Remote Code Execution (RCE) through the upload of PHP webshells.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34607
GHSA-2JG8-RMHM-XV9M

Affected Products

Emlog