New Path Traversal Vulnerability (CVE-2026-82599) Disclosed in SeaCMS

AI-generated NewsSnap summary based on source reporting.
Published: 2026-08-31
Category: technology
Source: NIST NVD

A path traversal vulnerability (CVE-2026-82599) has been identified in SeaCMS up to version 13.6. The flaw exists in the `unlink` function within the `/member.php?action=chgpwdsubmit` file, specifically in the Avatar Upload component. Manipulation of the `oldpic` argument can lead to remote exploitation, and an exploit is publicly available.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai