What is CVE-2026-18412?
A path traversal vulnerability exists in the OpenCart 4.2.0.0 extension installer. It extracts .ocmod.zip files without validating that paths stay within the target directory. Attackers can craft malicious extensions to write arbitrary files on the server. Users should avoid untrusted extensions and apply patches.
Azərbaycanca: OpenCart 4.2.0.0 uzantı quraşdırıcısında 'Path Traversal' zəifliyi aşkarlanıb. Təcavüzkar xüsusi hazırlanmış .ocmod.zip faylı vasitəsilə serverdə ixtiyari fayl yaza bilər. OpenCart istifadəçiləri dərhal etibarlı olmayan mənbələrdən uzantı quraşdırmağı dayandırmalı və rəsmi yeniləməni tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which version of OpenCart is affected by CVE-2026-18412?
This path traversal vulnerability has been identified in the extension installer of OpenCart version 4.2.0.0.
What should users do to protect themselves from CVE-2026-18412?
Users should immediately stop installing extensions from untrusted sources and apply the official patch.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.