Junglewise Threat Intelligence

CVE-2026-46687: Emlog Pro local file inclusion in article publishing interface

CVE-2026-46687 · Severity: info · CVSS 7.7 · Published 2026-07-16

Technologies: Emlog Pro. Vendors: Emlog.

Executive brief

Emlog is an open-source website building and blogging platform. A security flaw allows an authorized user (such as a blog author) to trick the system into running malicious code by manipulating how article templates are loaded. If an attacker can upload a file to the server through any means, they can use this vulnerability to take full control of the website and its data.

Technical details

A Local File Inclusion (LFI) vulnerability exists in Emlog Pro versions 2.6.13 and earlier due to improper validation of the 'template' parameter in the article publishing interface. The 'api_controller.php' script fails to sanitize path traversal sequences (../) before storing the template path in the database. When the article is subsequently viewed, 'log_controller.php' retrieves this path and passes it to 'View::getView()', which performs a direct PHP 'include'. An authenticated attacker with author privileges can exploit this to execute arbitrary PHP code, provided they have a method to upload a malicious file elsewhere on the server. No official patch has been identified at the time of this advisory.

Affected products

  • Emlog Emlog Pro <= 2.6.13

Timeline

  • 2026-05-13: advisory: Initial GitHub security advisory published
  • 2026-07-16: disclosed: CVE published to NVD dataset

References

Related threats