HIGH
Path Traversal Vulnerability in Bagisto
Published Jun 8, 2026
8.7
HIGHCVSS 4.0
EPSS 1.81%
Description
This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the filename parameter to access arbitrary files outside the intended directory on the targeted system.
Successful exploitation of this vulnerability could allow an attacker to read arbitrary sensitive files on the targeted system.
Affected products
-
- Version version v2.4.1StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade Bagisto to the patched version v2.4.2 or later.
https://github.com/bagisto/bagisto/tree/v2.4.2
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35036 Advisory
- https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0292 third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35036 | Advisory | |
| https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0292 | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-In
Published Jun 8, 2026
Updated Jun 8, 2026
Reserved May 25, 2026
Link CVE-2026-9506
CISA Vulnrichment
Updated Jun 8, 2026
ENISA EUVD
EUVD-2026-35036 Assigner CERT-In
Published Jun 8, 2026
Updated Jun 8, 2026
Exploited since n/a
Link EUVD-2026-35036