CVE-2026-64838: ICEcoder through 8.1 Path Traversal via oldFileName Parameter

Published Sep 10, 2026
·
Updated

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable by the PHP process into the web-accessible project directory, disclosing file contents and deleting originals.

Affected Software

1 affected component
icecoder ICEcoder<=8.1

Event History

Sep 10, 2026
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs an authenticated ICEcoder account with access to file move or rename operations. Exploitation is network-accessible, requires low privileges, and does not require user interaction.

2

What is the practical impact beyond reading files?

The attacker can move files writable by the PHP process from outside the document root into a web-accessible project directory. This can disclose their contents and deletes the original files as part of the move.

3

Are installations affected by default?

The provided information identifies ICEcoder versions through 8.1 as affected, but does not state whether the vulnerable file move and rename functionality is enabled or reachable in a default deployment.

4

How can I assess exposure while remediation is pending?

Review authenticated use of ICEcoder file move and rename operations, especially requests whose oldFileName value contains path traversal sequences. Also identify files outside the document root that are writable by the PHP process, since those are candidates for relocation and disclosure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203