CVE-2026-72604: Intelliants Subrion CMS - Path Traversal
A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server via the admin panel file deletion endpoint. The endpoint passes a user-supplied file path directly to unlink() without sanitization or path canonicalization. An authenticated administrator can delete sensitive system files outside the web root, potentially causing server instability or facilitating further attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72604?
The severity of CVE-2026-72604 is medium with a score of 6.5.
What type of vulnerability is CVE-2026-72604?
CVE-2026-72604 is a path traversal vulnerability.
Who can exploit CVE-2026-72604?
Authenticated administrators can exploit CVE-2026-72604 to delete arbitrary files on the server.
How do I fix CVE-2026-72604?
To fix CVE-2026-72604, ensure proper sanitization and canonicalization of user-supplied file paths in the file deletion endpoint.
What versions of Intelliants Subrion CMS are affected by CVE-2026-72604?
CVE-2026-72604 affects Intelliants Subrion CMS version 4.2.1.