CVE-2026-41517
Received Received - Intake
Arbitrary PHP Code Execution in Emlog

Publication date: 2026-05-08

Last updated on: 2026-05-08

Assigner: GitHub, Inc.

Description
Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server compromise and persistent backdoor installation. This issue has been patched in version 2.6.11.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-08
Last Modified
2026-05-08
Generated
2026-05-29
AI Q&A
2026-05-09
EPSS Evaluated
2026-05-28
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
emlog emlog to 2.6.11 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in Emlog, an open source website building system, in versions prior to 2.6.11. It involves insecure plugin upload functionality that allows attackers to upload and execute arbitrary PHP code on the server.

By exploiting this flaw, attackers can gain complete control over the server and install persistent backdoors.

The issue has been fixed in version 2.6.11.


How can this vulnerability impact me? :

Exploitation of this vulnerability can lead to complete server compromise.

Attackers can execute arbitrary PHP code, which may allow them to control the website, access sensitive data, modify content, or use the server for malicious purposes.

Additionally, attackers can install persistent backdoors, maintaining long-term unauthorized access.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, you should upgrade Emlog to version 2.6.11 or later, where the insecure plugin upload functionality has been patched.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability in Emlog allows attackers to upload and execute arbitrary PHP code, leading to complete server compromise and persistent backdoor installation. Such a compromise can result in unauthorized access to sensitive data, which may violate data protection requirements under standards like GDPR and HIPAA.

Because the vulnerability enables full server control, it increases the risk of data breaches, unauthorized data processing, and loss of data integrity and confidentiality, all of which are critical compliance concerns in regulations such as GDPR and HIPAA.

Therefore, organizations using vulnerable versions of Emlog prior to 2.6.11 may face compliance risks if this vulnerability is exploited.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart