CVE-2026-95264
Received Received - Intake

Directory Traversal in Feehi CMS Allows File Deletion

Vulnerability report for CVE-2026-95264, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: MITRE

Description

Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP process. Article image metadata is used to construct a filesystem path and is passed to `unlink()` without path traversal or directory validation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Feehi CMS 2.1.1 has a directory traversal vulnerability where an authenticated backend user with article edit permission can delete arbitrary files writable by the PHP process. The issue occurs because article image metadata is used to construct a filesystem path, which is passed to the unlink() function without proper validation or path traversal checks.

Detection Guidance

Check Feehi CMS logs for suspicious article update actions or file deletion attempts. Look for paths containing '..' or unusual file access patterns in common/models/Article.php and common/models/meta/ArticleMetaImages.php.

Impact Analysis

This vulnerability allows an attacker to delete critical files on the server, potentially causing denial of service or data loss. Files like configuration files or application data could be removed, disrupting service or exposing sensitive information.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by enabling unauthorized file deletion or access, potentially violating data integrity and confidentiality requirements. Organizations may face penalties if such breaches occur due to inadequate security measures.

Mitigation Strategies

Upgrade Feehi CMS to a patched version if available. Restrict article-edit permissions to trusted users only. Validate and sanitize all file paths in article image metadata before processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95264. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart