CVE-2026-3289: Sanluan PublicCMS Template Cache Generation TemplateCacheComponent.java saveMetadata path traversal
A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the component Template Cache Generation. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3289?
CVE-2026-3289 has been classified with a high severity due to its potential for path traversal attacks.
How do I fix CVE-2026-3289?
To fix CVE-2026-3289, you should update to the latest version of Sanluan PublicCMS that has patched this vulnerability.
What kind of attack can CVE-2026-3289 facilitate?
CVE-2026-3289 can facilitate path traversal attacks, allowing attackers to access restricted system files.
Which version of Sanluan PublicCMS is affected by CVE-2026-3289?
CVE-2026-3289 affects Sanluan PublicCMS version 6.202506.d.
What component of Sanluan PublicCMS is vulnerable in CVE-2026-3289?
The vulnerable component in CVE-2026-3289 is the Template Cache Generation within the TemplateCacheComponent.java file.