What is CVE-2026-55825?
In Contao CMS versions 5.7.0 through 5.7.6, an authenticated backend user can exploit a path traversal vulnerability by injecting `../` segments in the attachment identifier, allowing them to read files from other job directories within `var/job-attachments`. Users should upgrade to the latest patched version.
Azərbaycanca: Contao CMS-in 5.7.0-5.7.6 versiyalarında autentifikasiya olunmuş backend istifadəçisi `../` sequenceləri ilə attachment identifikatorunu manipulyasiya edərək `var/job-attachments` daxilindəki digər job qovluqlarından fayl oxuya bilər. İstifadəçilər Contao-nu ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of Contao CMS are affected by CVE-2026-55825?
Contao CMS versions 5.7.0 through 5.7.6 are affected by this path traversal vulnerability.
What privileges does an attacker need to exploit CVE-2026-55825?
The attacker must be an authenticated backend user.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.