What is CVE-2026-66914?
This critical vulnerability allows an unauthenticated path traversal attack in SEBLOD Joomla extension versions below 3.30.0, 4.7.0, and 6.0.1. An attacker can read files both inside and outside the webroot. Immediate update to the latest SEBLOD version is recommended.
Azərbaycanca: Bu kritik zəiflik SEBLOD Joomla genişlənməsinin 3.30.0, 4.7.0 və 6.0.1-dən aşağı versiyalarında autentifikasiya olunmamış 'path traversal' hücumuna imkan verir. Təcavüzkar veb kök qovluğu daxilində və xaricində faylları oxuya bilər. Dərhal SEBLOD-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of the SEBLOD extension are affected by CVE-2026-66914?
This critical path traversal vulnerability exists in SEBLOD Joomla extension versions below 3.30.0, 4.7.0, and 6.0.1.
What can an attacker achieve by exploiting CVE-2026-66914?
An unauthenticated attacker can read files both inside and outside the webroot.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.