File Read Vulnerability in Roadiz Content Management System
CVE-2026-33486

6.8MEDIUM

Key Information:

Vendor

Roadiz

Vendor
CVE Published:
26 March 2026

What is CVE-2026-33486?

A vulnerability in the Roadiz content management system prior to specified versions allows an authenticated attacker to access any file within the server's local file system that the web server can reach. This exposure puts sensitive information, such as environment variables, database credentials, and internal configuration files, at risk. The issue has been addressed in versions 2.7.9, 2.6.28, 2.5.44, and 2.3.42, which include necessary patches to mitigate this security concern.

Affected Version(s)

core-bundle-dev-app >= 2.7.0, < 2.7.9 < 2.7.0, 2.7.9

core-bundle-dev-app >= 2.6.0, < 2.6.28 < 2.6.0, 2.6.28

core-bundle-dev-app >= 2.4.0, < 2.5.44 < 2.4.0, 2.5.44

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.