CVE-2026-64838
ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated
CVSS
8.3
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 10 sept 2026 · Última mod.: 10 sept 2026 · CWE-22
Sin historial EPSS suficiente todavía.
ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable by the PHP process into the web-accessible project directory, disclosing file contents and deleting originals.
- github.comhttps://github.com/Caycon/cve-advisories/blob/main/2026/ICEcoder/CVE-2026-64838.md
- github.comhttps://github.com/icecoder/ICEcoder
- github.comhttps://github.com/icecoder/ICEcoder/blob/4a61847ef7bb0360735cf1d55c45e5de9746e24e/lib/file-control.php#L198
- www.vulncheck.comhttps://www.vulncheck.com/advisories/icecoder-through-8.1-path-traversal-via-oldfilename-parameter
- github.comhttps://github.com/Caycon/cve-advisories/blob/main/2026/ICEcoder/CVE-2026-64838.md
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-778077.5 ALT—
———The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires "Embed images" option in AcyMailing configuration being enabled.6hCVE-2026-860874.3 MED—
———IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.9hCVE-2026-848898.8 ALT—
———IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.9hCVE-2026-821009.6 CRÍ—
———IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.9hCVE-2026-815548.8 ALT—
———IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.9hCVE-2026-815518.8 ALT—
———IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.9h