Junglewise Threat Intelligence

CVE-2026-87727: a-blog cms path traversal in form file attachment

CVE-2026-87727 · Severity: medium · CVSS 6.5 · Published 2026-09-11

Executive brief

a-blog cms is a content management system that includes form functionality with file attachment capabilities. An unauthenticated attacker can exploit a path traversal vulnerability in the form attachment feature to read or delete arbitrary files on the server, potentially exposing sensitive configuration data, database credentials, personal information, or disrupting website operations.

Technical details

The vulnerability exists in the form attachment handling functionality of a-blog cms. An unauthenticated attacker can send a crafted request to the form confirmation screen containing path traversal sequences, allowing the attacker to read, copy, or delete files outside the intended upload directory. The vulnerability is only exploitable when file attachment to administrator emails is enabled in form settings. No authentication is required, but a publicly accessible form with this feature enabled must be present. Patches are available for versions 3.0.63+, 3.1.76+, and 3.2.33+; versions 2.11 and earlier are end-of-life with no security updates available.

Affected products

  • appleple inc. a-blog cms 3.2.33 and earlier

Timeline

  • 2026-09-11: disclosed: Vulnerability disclosed via JVN#20829034 and published on NVD

References