What is CVE-2026-63667?
CVE-2026-63667 is a vulnerability in the import-export module of ApostropheCMS where an attachment source path is constructed using attacker-controlled fields without sanitization. This path traversal could allow an authenticated user to read arbitrary files on the server, and it is fixed by upgrading to version 3.6.2.
Azərbaycanca: CVE-2026-63667 ApostropheCMS-in idxal/ixrac modulunda zəiflikdir. _id, name və extension sahələrindən istifadə edərək fayl yolu manipulyasiyası mümkündür. Bu, autentifikasiya olunmuş istifadəçiyə serverdə ikili faylları oxumağa imkan verə bilər, versiya 3.6.2-yə yeniləməklə aradan qaldırılır.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What level of access is required to exploit CVE-2026-63667 in ApostropheCMS?
This vulnerability can be exploited by an authenticated user.
In which version of ApostropheCMS is CVE-2026-63667 fixed?
It is fixed by upgrading to version 3.6.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.