CVE-2026-72604

Source
https://cve.org/CVERecord?id=CVE-2026-72604
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72604.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72604
Published
2026-08-11T11:15:25.006Z
Modified
2026-08-13T04:02:36.748697345Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
Intelliants Subrion CMS - Path Traversal
Details

A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server via the admin panel file deletion endpoint. The endpoint passes a user-supplied file path directly to unlink() without sanitization or path canonicalization. An authenticated administrator can delete sensitive system files outside the web root, potentially causing server instability or facilitating further attacks.

Database specific
{
    "cna_assigner": "TuranSec",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72604.json"
}
References

Affected packages

Git / github.com/intelliants/subrion

Affected ranges

Type
GIT
Repo
https://github.com/intelliants/subrion
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.2.1"
        },
        {
            "fixed": "4.2.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.1.0
v4.1.4
v4.1.5
v4.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72604.json"