Path Traversal Vulnerability in UBB.threads by UBB
CVE-2026-54223
8.6HIGH
What is CVE-2026-54223?
UBB.threads, a product of UBB, is susceptible to a path traversal vulnerability, allowing users with the ability to edit templates to manipulate file paths on the server. This could enable unauthorized access to read and write any files that the application has permission to, potentially leading to remote code execution. The vulnerability has been validated in version 7.7.5, but there may be implications for other versions as well.
Affected Version(s)
UBB.threads 0 <= 7.7.5
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kamil Szczurowski (Securitum)
Michał Wnękowicz (Securitum)
