Security Advisory

CVE-2026-46687

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-16 17:01:31
Last updated 2026-07-16 17:54:49
Assigner GitHub_M
CVSS score 7.7
State PUBLISHED

Description

Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, and log_controller.php later checks file_exists and calls include View::getView($template), allowing an authenticated author to include an arbitrary local .php file when an article is viewed. No fixed version is currently identified.