Junglewise Threat Intelligence

CVE-2026-50776: Pronis Loisirs Billetterie CSE directory traversal

CVE-2026-50776 · Severity: high · CVSS 7.5 · Published 2026-08-17

Executive brief

Pronis Loisirs Billetterie is a ticketing and employee benefits management platform used by corporate social committees (CSE) in France. A directory traversal vulnerability allows unauthenticated remote attackers to read sensitive server files—including system configuration and SSH credentials—and potentially execute arbitrary code, threatening the confidentiality of employee and organizational data.

Technical details

A directory traversal vulnerability exists in the getfile.php endpoint that fails to properly validate user-supplied file path input. An attacker can exploit this by submitting path traversal sequences (e.g., "../../../") to access files outside the intended directory, such as /etc/passwd and configuration files containing SSH credentials. The vulnerability is network-accessible without authentication and can lead to information disclosure and potentially arbitrary code execution. No patch availability is documented in the advisory.

Affected products

  • Pronis Loisirs Billetterie CSE < 04/2026

Timeline

  • 2026-08-17: disclosed: CVE-2026-50776 published on NVD

References