Web Application Vulnerability in Emlog by CodeCanyon
CVE-2026-73849
What is CVE-2026-73849?
Emlog, an open-source content management system, has a significant vulnerability that allows unauthorized actions via the install.php script. Specifically, versions 2.6.26 and earlier do not perform adequate authentication checks when the action 'reinstall' is triggered. This oversight enables an attacker to exploit the system by providing a malicious request containing database configuration parameters. As a result, the attacker can overwrite critical files, such as 'config.php', with their own data, effectively compromising the application's settings and creating unauthorized administrative access. Currently, no patches or fixes are available for this vulnerability, highlighting the importance of monitoring and securing Emlog installations.
Affected Version(s)
emlog <= 2.6.26
