CVE-2026-53757: Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE

Published Sep 4, 2026
·
Updated

Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry paths for ../ traversal sequences. Only the first entry's subdirectory structure is checked. An attacker can overwrite arbitrary files on the server filesystem, including config.php for immediate RCE. At time of publication, there are no publicly known patches.

Affected Software

1 affected component
Emlog emlog<=2.6.29

Event History

Sep 4, 2026
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
DescriptionWeakness

Frequently Asked Questions

1

Which versions should be treated as affected?

Emlog version 2.6.29 and all earlier versions are affected.

2

What access does an attacker need to exploit this issue?

The attacker needs to be able to upload a plugin or template ZIP archive. A crafted archive can include traversal paths that are extracted outside the intended directory.

3

Is a patch available?

At the time of publication, no publicly known patches were available.

4

What is the potential impact of successful exploitation?

An attacker can overwrite arbitrary files on the server filesystem. Overwriting config.php can result in immediate remote code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203