Path Traversal Vulnerability in Formwork BackupController
CVE-2026-104478
7.1HIGH
What is CVE-2026-104478?
The Formwork application, specifically versions prior to 2.3.13, is susceptible to a path traversal vulnerability within its BackupController. This flaw enables authenticated panel users with backup download or delete permissions to inadvertently access or manipulate arbitrary files outside of the intended backup directory. By exploiting a base64-encoded backslash-separated traversal payload, attackers can circumvent the PHP basename function on Linux, potentially leading to unauthorized file read or deletion operations. Users are recommended to update to the latest version to mitigate this risk.
Affected Version(s)
formwork 0 < 2.3.13
formwork 2.3.13
