Junglewise Threat Intelligence

CVE-2026-53698: Silverpeas path traversal in Personal space feature

CVE-2026-53698 · Severity: medium · CVSS 6.5 · Published 2026-06-10

Technologies: org.silverpeas.core:silverpeas-core-war (Maven), org.silverpeas.core:silverpeas-core (Maven). Vendors: Maven.

Executive brief

Silverpeas is a collaborative portal software used for document management and team workspaces. When no component ID is provided, the application incorrectly handles the "Personal space" feature, allowing authenticated users to access files outside their intended directory through path traversal. This could expose sensitive documents and configuration files stored on the server.

Technical details

This vulnerability is an absolute path traversal (CWE-36) in the FileServer servlet component. When a request is made without a componentId parameter, the application fails to properly validate and sanitize file paths, allowing an attacker to construct requests that access files outside the intended "Personal space" directory. The vulnerability requires authentication (low privilege level) and no user interaction, accessed over the network via HTTP requests. An authenticated attacker can read arbitrary files with high confidentiality impact. The vulnerability was fixed in version 6.4.7, as indicated by the commit caa6e6d and the subsequent release tag.

Affected products

  • Silverpeas Silverpeas Core ≤ 6.4.6
  • Silverpeas Silverpeas Core WAR ≤ 6.4-feature13197

Timeline

  • 2026-06-10: disclosed
  • 2026-07-16: patched: Fixed in version 6.4.7

References

Related threats