HIGH
LibreBooking path traversal
Published Jul 9, 2026
8.6
HIGHCVSS 4.0
EPSS 1.02%
Description
LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. Fixed in 5.1.0.
Affected products
-
- Version 0StatusaffectedConstraints<5.1.0
- Version 5.1.0StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| LibreBooking | LibreBooking | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42662 Advisory
- https://github.com/LibreBooking/librebooking/commit/cb9b7ad9da0243bd105809f6a4a8a6b9147c71ea patch
- https://github.com/LibreBooking/librebooking/pull/1456 patch
- https://github.com/LibreBooking/librebooking/releases/tag/v5.1.0 release-notes
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-01.json third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2026-61343 vdb-entry
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisa-cg
Published Jul 9, 2026
Updated Jul 30, 2026
Reserved Jul 8, 2026
Link CVE-2026-61343
CISA Vulnrichment
Updated Jul 21, 2026
ENISA EUVD
EUVD-2026-42662 Assigner cisa-cg
Published Jul 9, 2026
Updated Jul 30, 2026
Exploited since n/a
Link EUVD-2026-42662