File Read Vulnerability in Roadiz Content Management System
CVE-2026-33486
6.8MEDIUM
What is CVE-2026-33486?
A vulnerability in the Roadiz content management system prior to specified versions allows an authenticated attacker to access any file within the server's local file system that the web server can reach. This exposure puts sensitive information, such as environment variables, database credentials, and internal configuration files, at risk. The issue has been addressed in versions 2.7.9, 2.6.28, 2.5.44, and 2.3.42, which include necessary patches to mitigate this security concern.
Affected Version(s)
core-bundle-dev-app >= 2.7.0, < 2.7.9 < 2.7.0, 2.7.9
core-bundle-dev-app >= 2.6.0, < 2.6.28 < 2.6.0, 2.6.28
core-bundle-dev-app >= 2.4.0, < 2.5.44 < 2.4.0, 2.5.44
