CVE-2026-88392
Received Received - Intake

Directory Traversal in Unimall v4 FileUploadController

Vulnerability report for CVE-2026-88392, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: MITRE

Description

Unimall v4 is vulnerable to Directory Traversal in FileUploadController.local(). This allows an attacker to execute arbitrary code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-88392 is a Directory Traversal vulnerability in Unimall v4 affecting the FileUploadController.local() method. It allows an attacker to write files to arbitrary paths on the server by exploiting improper path validation during file uploads. The ADMINTOKEN header is present but only checks for a regular user session, not admin privileges. Since user registration is open, any attacker can exploit this by creating an account and uploading malicious files.

Detection Guidance

To detect this vulnerability, monitor for unauthorized file uploads or suspicious POST requests to the FileUploadController endpoint. Check server logs for requests containing the ADMINTOKEN header with manipulated file paths. Look for unexpected files in system directories or web application folders.

Impact Analysis

This vulnerability can lead to remote code execution (RCE) or persistence on Windows systems by writing malicious files to sensitive locations like the Startup folder or overwriting system files. Attackers can also overwrite existing files, causing data corruption or denial of service. The impact includes full system compromise if the attacker gains control over critical files.

Compliance Impact

This vulnerability can lead to non-compliance with GDPR and HIPAA by enabling unauthorized access to sensitive data. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. A successful exploit could result in data breaches, unauthorized modifications, or loss of data integrity, all of which violate these regulations.

Mitigation Strategies

Immediately disable open user registration to prevent unauthorized access. Validate and sanitize all file upload paths in FileUploadController.local(). Implement strict path validation to restrict uploads to designated directories only. Ensure ADMINTOKEN header checks enforce admin-level permissions, not just user sessions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88392. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart