Executive brief
Mautic, an open-source marketing automation platform, is affected by a security flaw in its campaign import feature. An authorized user could upload a specially crafted file that bypasses security restrictions to place malicious code on the server. If exploited, this allows an attacker to take full control of the system, potentially leading to data theft, service disruption, or unauthorized access to customer marketing data.
Technical details
A path traversal vulnerability (CWE-22) exists in Mautic 7.x within the campaign import functionality. The root cause is a flaw in the validation logic when extracting uploaded ZIP files, which fails to prevent file paths from escaping the intended temporary directory. An authenticated attacker with 'campaign:imports:create' privileges can exploit this to write arbitrary PHP files to sensitive system directories, such as configuration or cache folders. This leads to Remote Code Execution (RCE) under the context of the web server user. The issue is patched in version 7.1.2.
Affected products
- Mautic Mautic Core >= 7.0.0, < 7.1.2
Timeline
- 2026-05-29: disclosed: NVD publication date
- 2026-07-02: advisory: GitHub Advisory published
- 2026-07-02: patched: Version 7.1.2 released