CVE-2026-6570: kodcloud KodExplorer systemMember.class.php initInstall authorization
A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argument path results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6570?
CVE-2026-6570 is assessed as a high severity vulnerability due to its potential to allow unauthorized access and manipulate system operations.
How do I fix CVE-2026-6570?
To fix CVE-2026-6570, update KodExplorer to version 4.53 or later where the vulnerability is addressed.
What versions of KodExplorer are affected by CVE-2026-6570?
KodExplorer versions up to and including 4.52 are affected by CVE-2026-6570.
What component of KodExplorer does CVE-2026-6570 impact?
CVE-2026-6570 impacts the initInstall function within the systemMember.class.php file.
What type of vulnerability is CVE-2026-6570?
CVE-2026-6570 is an authorization flaw that allows manipulation of the argument path leading to security issues.