Web Application Vulnerability in Emlog by CodeCanyon
CVE-2026-73849

9.8CRITICAL

Key Information:

Vendor

Emlog

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-73849?

Emlog, an open-source content management system, has a significant vulnerability that allows unauthorized actions via the install.php script. Specifically, versions 2.6.26 and earlier do not perform adequate authentication checks when the action 'reinstall' is triggered. This oversight enables an attacker to exploit the system by providing a malicious request containing database configuration parameters. As a result, the attacker can overwrite critical files, such as 'config.php', with their own data, effectively compromising the application's settings and creating unauthorized administrative access. Currently, no patches or fixes are available for this vulnerability, highlighting the importance of monitoring and securing Emlog installations.

Affected Version(s)

emlog <= 2.6.26

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.