Path Traversal Vulnerability in UBB.threads by UBB
CVE-2026-54223

8.6HIGH

Key Information:

Vendor
CVE Published:
18 June 2026

What is CVE-2026-54223?

UBB.threads, a product of UBB, is susceptible to a path traversal vulnerability, allowing users with the ability to edit templates to manipulate file paths on the server. This could enable unauthorized access to read and write any files that the application has permission to, potentially leading to remote code execution. The vulnerability has been validated in version 7.7.5, but there may be implications for other versions as well.

Affected Version(s)

UBB.threads 0 <= 7.7.5

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamil Szczurowski (Securitum)
Michał Wnękowicz (Securitum)
.