CVE-2026-22799: emlog Arbitrary File Upload Vulnerability

Published Jan 12, 2026
·
Updated

Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The endpoint fails to implement proper validation of file types, extensions, and content, allowing authenticated attackers (with a valid API key or admin session cookie) to upload arbitrary files (including malicious PHP scripts) to the server. An attacker can obtain the API key either by gaining administrator access to enable the REST API setting, or via information disclosure vulnerabilities in the application. Once uploaded, the malicious PHP file can be executed to gain remote code execution (RCE) on the target server, leading to full server compromise.

Affected Software

2 affected components
Emlog emlog<=2.6.1
Emlog emlog<2.6.1

Event History

Jan 12, 2026
CVE Published
via MITRE·10:05 PM
Data Sourced
via MITRE·10:05 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 19, 58052
Event
via FIRST·07:14 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-22799?

CVE-2026-22799 is classified as a critical severity vulnerability due to its potential for arbitrary file upload.

2

How do I fix CVE-2026-22799?

To fix CVE-2026-22799, upgrade Emlog to version 2.6.2 or later, which includes a patch for this vulnerability.

3

Who is affected by CVE-2026-22799?

CVE-2026-22799 affects all installations of Emlog version 2.6.1 and earlier.

4

What is the impact of CVE-2026-22799?

The impact of CVE-2026-22799 includes the potential for unauthorized access and execution of malicious files on the server.

5

Is authentication required to exploit CVE-2026-22799?

No, authentication is not required to exploit CVE-2026-22799, making it particularly dangerous for unprotected endpoints.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203