CVE-2026-87727: Path Traversal
Published Sep 11, 2026
·Updated
a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated attacker to read or delete arbitrary files on the affected product.
Affected Software
1 affected component
a-blog cms<=3.2.33
Event History
Sep 11, 2026
CVE Published
via MITRE·08:14 AM
Data Sourced
via MITRE·08:14 AM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated attacker can exploit the vulnerability over the network. No user interaction or prior privileges are required.
2
Which deployments are affected?
a-blog cms version 3.2.33 and earlier is affected. The provided information does not identify any configuration prerequisite or mitigation setting.
3
What is the potential impact?
An attacker may read or delete arbitrary files on the affected product. The supplied information indicates confidentiality and integrity impact, with no availability impact.