Low severity2.7NVD Advisory· Published Apr 17, 2026· Updated Apr 20, 2026
CVE-2026-35496
CVE-2026-35496
Description
A path traversal vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to access higher-level directories that should not be accessible.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/jp/JVN78422311/nvdThird Party Advisory
- community.cubecart.com/t/cubecart-6-6-0-released-the-biggest-update-in-years/62405nvdRelease Notes
News mentions
0No linked articles in our index yet.