CVE-2026-39276: Emlog

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default template files or directly include malicious code files in the current template.

Affected products

  • Emlog Emlog: version 2.6.9 only

Published 2026-05-29. Last modified 2026-07-21.