CVE-2026-35496: Path Traversal
Published Apr 17, 2026
·Updated
A path traversal vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to access higher-level directories that should not be accessible.
Affected Software
2 affected components
Cubecart CubeCart<6.6.0
Cubecart CubeCart<6.6.0
Event History
Apr 17, 2026
CVE Published
via MITRE·04:33 AM
Data Sourced
via MITRE·04:33 AM
DescriptionSeverity
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-35496?
CVE-2026-35496 is classified as a moderate severity path traversal vulnerability.
2
How do I fix CVE-2026-35496?
To fix CVE-2026-35496, upgrade CubeCart to version 6.6.0 or later.
3
Who is affected by CVE-2026-35496?
CVE-2026-35496 affects users of CubeCart versions prior to 6.6.0 with administrative privileges.
4
What type of vulnerability is CVE-2026-35496?
CVE-2026-35496 is a path traversal vulnerability that can allow unauthorized directory access.
5
Can CVE-2026-35496 lead to data exposure?
Yes, CVE-2026-35496 can potentially allow unauthorized access to sensitive files in higher-level directories.