Junglewise Threat Intelligence

CVE-2026-54223: UBB Systems UBB.threads Path Traversal in Template Editor

CVE-2026-54223 · Severity: info · CVSS 8.6 · Published 2026-06-18

Technologies: UBB Systems UBB.threads. Vendors: UBB Systems.

Executive brief

UBB.threads, a forum and community software platform, contains a security flaw that allows high-privileged users to access or modify any file on the underlying server. By exploiting this path traversal vulnerability, an administrator or user with template-editing permissions could take full control of the server and execute malicious code. This could lead to a total compromise of the application, including the theft of user data or a complete service shutdown.

Technical details

A path traversal vulnerability (CWE-22) exists in UBB.threads through version 7.7.5. The flaw is located in the template editing functionality, where insufficient input validation allows an authenticated user with high privileges (specifically the ability to edit templates) to escape the intended directory. An attacker can leverage this to read or write arbitrary files that the web server process has permissions to access. This capability can be further escalated to achieve Remote Code Execution (RCE) on the host server. As the vendor has not responded to disclosure attempts, no official patch is currently available.

Affected products

  • UBB Systems UBB.threads All versions through 7.7.5

Timeline

  • 2026-06-18: disclosed: Vulnerability disclosed by CERT Polska
  • 2026-06-18: advisory: CVE-2026-54223 published

References

Related threats