Path Traversal Vulnerability in Formwork BackupController
CVE-2026-104478

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104478?

The Formwork application, specifically versions prior to 2.3.13, is susceptible to a path traversal vulnerability within its BackupController. This flaw enables authenticated panel users with backup download or delete permissions to inadvertently access or manipulate arbitrary files outside of the intended backup directory. By exploiting a base64-encoded backslash-separated traversal payload, attackers can circumvent the PHP basename function on Linux, potentially leading to unauthorized file read or deletion operations. Users are recommended to update to the latest version to mitigate this risk.

Affected Version(s)

formwork 0 < 2.3.13

formwork 2.3.13

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Islomjon Tursunov
.