What is CVE-2026-65694?
A path traversal vulnerability exists in the static file controller of Microweber CMS through version 2.0.20, allowing unauthenticated remote attackers to read arbitrary files via a specially crafted HTTP GET request with directory traversal sequences. Users should immediately update to the latest patched version.
Azərbaycanca: Microweber CMS-in 2.0.20 versiyasına qədər olan sistemlərdə "static file controller"-də yol keçmə (path traversal) zəifliyi aşkarlanıb. Bu, autentifikasiya olunmamış uzaq təcavüzkara sadə HTTP GET sorğusu göndərərək serverdəki ixtiyari faylları oxumağa imkan verir. Dərhal CMS-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ1
Which versions of Microweber CMS are affected by CVE-2026-65694?
Microweber CMS through version 2.0.20 is affected by this path traversal vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.