Path Traversal Vulnerability in weiqingwen spring-boot-forum Avatar Upload Component
CVE-2026-96678
Key Information:
- Vendor
Weiqingwen
- Status
- Vendor
- CVE Published:
- 23 September 2026
Badges
What is CVE-2026-96678?
A security flaw has been identified in the Avatar Upload component of the weiqingwen spring-boot-forum, specifically within the validate function of the NewUserFormValidator.java file. Attackers can leverage this vulnerability by manipulating the Username argument, potentially conducting remote attacks that allow unauthorized access to sensitive files. Despite the vendor being informed of the issue promptly, there has been no response regarding mitigation or patching efforts. The continuous delivery model employed by the product complicates version tracking, leaving users uncertain about which releases might be affected or fixed.
Affected Version(s)
spring-boot-forum 538eecc3c6b85fdf0768ab4e8354b48c0c17d94f
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
