Junglewise Threat Intelligence

CVE-2026-82599: SeaCMS arbitrary file deletion in avatar upload

CVE-2026-82599 · Severity: medium · CVSS 5.4 · Published 2026-08-31

Technologies: Seacms. Vendors: Seacms.

Executive brief

SeaCMS is a content management system that allows authenticated users to upload profile avatars. A flaw in the avatar upload feature allows an authenticated attacker to delete arbitrary files on the server by crafting a malicious file path in the upload request, potentially leading to data loss or system compromise if critical files are targeted.

Technical details

This is a path traversal vulnerability combined with arbitrary file deletion in SeaCMS 13.6's member avatar upload functionality (/member.php?action=chgpwdsubmit). The vulnerable component fails to validate or sanitize the oldpic parameter before passing it directly to PHP's unlink() function. An authenticated, low-privileged member can bypass the deletion restriction by uploading a valid image while specifying a malicious oldpic path containing traversal sequences (e.g., ../../ or absolute paths), allowing deletion of files outside the intended uploads/user/ directory. The vulnerability requires the avatar upload feature to be enabled (cfg_upic='1') and an authenticated session; no additional user interaction is required. An attacker can delete arbitrary files writable by the web process, including application files, configuration files, or other user data.

Affected products

  • SeaCMS SeaCMS up to 13.6

Timeline

  • 2026-08-31: disclosed
  • other: Public exploit available

References

Related threats