VYPR
Medium severity6.5NVD Advisory· Published Jun 25, 2026· Updated Jun 28, 2026

CVE-2026-48944

CVE-2026-48944

Description

The K2 frontend article-save handler accepts an attachment[N][existing] POST field that is concatenated with JPATH_SITE/ and passed to JFile::copy(). JPath::clean does NOT strip .., and there is no allow-list of source paths. An Author can therefore copy configuration.php (or any other file readable by the web user — including ../../../etc/passwd) into /media/k2/attachments/, then retrieve the contents via the K2 attachment-download endpoint.

Affected products

1
  • cpe:2.3:a:joomlaworks:k2:*:*:*:*:*:joomla\!:*:*
    Range: <=2.26

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.