What is CVE-2026-53976?
CVE-2026-53976 is a path traversal vulnerability in OpenChamber 1.11.7, affecting the `/api/fs/read`, `/api/fs/stat`, and `/api/fs/raw` file-serving endpoints. By supplying the `allowOutsideWorkspace=true` query parameter with an absolute path, unauthenticated remote attackers can read arbitrary files on the system. Users should immediately update OpenChamber to the latest patched version or restrict access to these endpoints.
Azərbaycanca: CVE-2026-53976, OpenChamber 1.11.7 versiyasının `allowOutsideWorkspace=true` parametri ilə fayl oxuma endpoint-lərində (`/api/fs/read`, `/api/fs/stat`, `/api/fs/raw`) mövcud olan path traversal zəifliyidir. Bu boşluq autentifikasiya olunmamış uzaqdan hücumçulara mütləq yol təqdim edərək sistemdəki ixtiyari faylları oxumağa imkan verir. İstifadəçilər dərhal OpenChamber-i ən son versiyaya yeniləməli və ya müvəqqəti olaraq həmin endpoint-lərə girişi məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which version of OpenChamber is affected by CVE-2026-53976?
CVE-2026-53976 affects OpenChamber version 1.11.7.
Is authentication required to exploit this vulnerability?
No, unauthenticated remote attackers can read arbitrary files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.