Remote Code Execution Vulnerability in Emlog CMS
CVE-2026-22799
9.3CRITICAL
What is CVE-2026-22799?
Emlog, an open-source website building platform, contains a vulnerability in its REST API endpoint that permits unauthorized file uploads. Versions up to 2.6.1 are affected, where the upload endpoint does not properly validate file types or content. This weakness allows authenticated attackers, who possess a valid API key or an admin session cookie, to upload arbitrary files, including potentially malicious PHP scripts. An attacker can exploit this flaw to gain remote code execution, leading to a full compromise of the server. The API key may be obtained either through obtaining administrative access or exploiting other vulnerabilities within the application.
Affected Version(s)
emlog <= 2.6.1
