Medium severity6.5NVD Advisory· Published Jun 25, 2026· Updated Jun 28, 2026
CVE-2026-48944
CVE-2026-48944
Description
The K2 frontend article-save handler accepts an attachment[N][existing] POST field that is concatenated with JPATH_SITE/ and passed to JFile::copy(). JPath::clean does NOT strip .., and there is no allow-list of source paths. An Author can therefore copy configuration.php (or any other file readable by the web user — including ../../../etc/passwd) into /media/k2/attachments/, then retrieve the contents via the K2 attachment-download endpoint.
Affected products
1Patches
Vulnerability mechanics
References
1- www.getk2.orgnvdProduct
News mentions
0No linked articles in our index yet.