Unauthenticated Path Traversal Vulnerability in SEBLOD Joomla Extension
CVE-2026-66914
9.2CRITICAL
What is CVE-2026-66914?
The SEBLOD Joomla Extension contains a vulnerability that allows an unauthenticated attacker to exploit path traversal weaknesses. This flaw enables unauthorized individuals to download files located both within and outside the webroot directory of the application. Due to the lack of proper authentication checks, sensitive information can be exposed, potentially leading to further exploitation of the server.
Affected Version(s)
SEBLOD extension for Joomla 1.0.0-3.29.0
SEBLOD extension for Joomla 4.0.0-4.6.0
SEBLOD extension for Joomla 5.0.0-6.0.0
