Path Traversal Vulnerability in ICEcoder by ICEcoder Team
CVE-2026-64838

8.7HIGH

Key Information:

Vendor

Icecoder

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-64838?

The vulnerability in ICEcoder up to version 8.1 arises from inadequate validation of the oldFileName parameter during file move and rename operations. This flaw permits authenticated users to exploit path traversal sequences, enabling them to relocate files that are writable by the PHP process into the project's web-accessible directory. Consequently, attackers can gain access to sensitive file content, potentially leading to unauthorized disclosures or even file deletions.

Affected Version(s)

ICEcoder 8.0 <= 8.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ByteMe.Red
.