Junglewise Threat Intelligence

CVE-2026-93468: HGiga OAKlouds arbitrary file read via path traversal

CVE-2026-93468 · Severity: high · CVSS 7.5 · Published 2026-09-18

Executive brief

HGiga OAKlouds is a content management platform used to host and manage website pages and bulletins. An unauthenticated attacker can exploit a relative path traversal flaw in the bulletin module to read sensitive system files directly from the server, exposing confidential configuration data, credentials, and other protected information without authentication.

Technical details

The OAKlouds bulletin_v3 module contains a path traversal vulnerability (CWE-23) that allows unauthenticated remote attackers to read arbitrary system files. The vulnerability exists in the bulletin_v3 component versions 2.0 and 3.0 (before version 107 in both cases), where insufficient input validation on relative path parameters enables traversal attacks. An attacker can send specially crafted requests with relative path sequences (e.g., ../) to escape the intended directory and access system files outside the intended scope. No authentication, special interaction, or preconditions are required to exploit this vulnerability. The attacker gains read-only access to sensitive files, potentially exposing credentials, configuration data, and other confidential information. Patches are available: update OAKlouds-bulletin_v3-2.0 and 3.0 to version 107 or later.

Affected products

  • HGiga OAKlouds bulletin_v3-2.0 before 107
  • HGiga OAKlouds bulletin_v3-3.0 before 107

Timeline

  • 2026-09-18: disclosed

References