Remote Code Execution Vulnerability in Emlog CMS
CVE-2026-22799

9.3CRITICAL

Key Information:

Vendor

Emlog

Status
Vendor
CVE Published:
12 January 2026

What is CVE-2026-22799?

Emlog, an open-source website building platform, contains a vulnerability in its REST API endpoint that permits unauthorized file uploads. Versions up to 2.6.1 are affected, where the upload endpoint does not properly validate file types or content. This weakness allows authenticated attackers, who possess a valid API key or an admin session cookie, to upload arbitrary files, including potentially malicious PHP scripts. An attacker can exploit this flaw to gain remote code execution, leading to a full compromise of the server. The API key may be obtained either through obtaining administrative access or exploiting other vulnerabilities within the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

emlog <= 2.6.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.