CVE-2026-55231
Deferred Deferred - Pending Action

Authenticated File Read and Deletion in Vvveb CMS

Vulnerability report for CVE-2026-55231, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel user who holds backup access (default role site_admin or higher) read and delete arbitrary files on a server. An attacker can recover database credentials from config/db.php, read host files such as /etc/passwd, and delete config/db.php to push a site back into install mode for a full takeover. This issue has been patched in version 1.0.8.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vvveb vvveb to 1.0.8.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55231 is a path traversal vulnerability in the Vvveb CMS affecting versions 1.0.8.5 and earlier. The flaw exists in the sanitizeFileName() function, which fails to properly block directory traversal sequences due to an incomplete regex replacement. An authenticated admin user with backup access can exploit this to read or delete arbitrary files on the server.

Detection Guidance

Check if your Vvveb CMS version is below 1.0.8.6. Inspect the sanitizeFileName() function in the code for incomplete regex replacement that allows bypassing directory traversal checks. Look for backup access roles (site_admin or higher) and verify if realpath() is used for containment.

Impact Analysis

An attacker can read sensitive files like /etc/passwd or config/db.php (containing database credentials), delete critical files such as config/db.php to force the application into install mode for a full takeover, or escape role boundaries in multi-tenant deployments.

Mitigation Strategies

Upgrade Vvveb CMS to version 1.0.8.6 or later immediately. Remove backup access from non-admin users. Implement additional file access controls and review file deletion permissions. Monitor for unauthorized file reads or deletions in system logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55231. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart