Path Traversal Vulnerability in JeeSite by ThinkGem
CVE-2026-36762
8.8HIGH
What is CVE-2026-36762?
An exposed vulnerability exists in JeeSite v5.15.1 within the fileEntityId parameter of the /a/file/upload endpoint. Authenticated users with file upload permissions can leverage this issue to perform path traversal attacks. This allows them to write arbitrary files with permitted suffixes to unauthorized locations on the filesystem, potentially leading to further exploitation of the server.
