CVE-2026-41517: Emlog: Remote Code Execution via Malicious Plugin Upload
Published May 8, 2026
·Updated
Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server compromise and persistent backdoor installation. This issue has been patched in version 2.6.11.
Affected Software
1 affected component
Emlog emlog<2.6.11
Event History
May 8, 2026
CVE Published
via MITRE·09:50 PM
Data Sourced
via MITRE·09:50 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-41517?
CVE-2026-41517 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2026-41517?
To fix CVE-2026-41517, upgrade Emlog to version 2.6.11 or later.
3
What are the consequences of exploiting CVE-2026-41517?
Exploiting CVE-2026-41517 allows attackers to upload and execute arbitrary PHP code, which can lead to complete server compromise.
4
Which versions of Emlog are affected by CVE-2026-41517?
CVE-2026-41517 affects all versions of Emlog prior to 2.6.11.
5
Is there a patch available for CVE-2026-41517?
Yes, upgrading to Emlog version 2.6.11 or later resolves CVE-2026-41517.