Junglewise Threat Intelligence

CVE-2026-77807: AcyMailing directory traversal in user name parameter

CVE-2026-77807 · Severity: high · CVSS 7.5 · Published 2026-09-11

Technologies: Acyba AcyMailing. Vendors: Acyba.

Executive brief

AcyMailing is a popular WordPress plugin used for email newsletters and marketing automation. An unauthenticated attacker can exploit a directory traversal vulnerability to read arbitrary files from the server, potentially exposing sensitive configuration data, database credentials, or other confidential information—but only if the "Embed images" feature is enabled in plugin settings.

Technical details

The vulnerability is a directory traversal (path traversal) flaw in the `user[name]` parameter affecting AcyMailing versions up to 11.0.4. The vulnerability allows unauthenticated attackers to request arbitrary file paths on the server. The attack vector is network-based and requires only that the "Embed images" option be enabled in the plugin's configuration; no authentication is required. An attacker can read arbitrary files from the server, potentially accessing configuration files containing database credentials or other sensitive data. A patch addressing this issue is available in versions after 11.0.4.

Affected products

  • Acyba AcyMailing up to 11.0.4

Timeline

  • 2026-09-11: disclosed

References

Related threats