Path Traversal Vulnerability in MineAdmin Backend Management System
CVE-2026-55224

8.7HIGH

Key Information:

Vendor

Mineadmin

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-55224?

The MineAdmin backend management system contains a vulnerability that allows an attacker to exploit unsanitized user-supplied identifiers used in file system paths. This flaw enables the possibility of path traversal, where an attacker can manipulate file paths to access directories outside of the intended scope. By employing path traversal sequences, such as '../', malicious users can potentially read from, write to, or execute operations on files in arbitrary directories, including the installation and uninstallation of plugins. This vulnerability has been effectively addressed in version 3.2.0-alpha.2, ensuring improved security for users.

Affected Version(s)

MineAdmin < 3.2.0-alpha.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.