<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Path-Traversal — PoC Archive</title><link>https://poc.intelseclab.com/tags/path-traversal/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/path-traversal/index.xml" rel="self" type="application/rss+xml"/><item><title>UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-34910-unifi-os-unauth-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-34910-unifi-os-unauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-34910, CVE-2026-34909, CVE-2026-34908. Status: Patched. Affects: Ubiquiti UniFi OS Server. Tags: ubiquiti, unifi, unifi-os, auth-bypass, path-traversal, command-injection, rce, unauth, kev, mirai, nginx, CVE-2026-34910.</description><category>network</category><category>Critical</category><category>ubiquiti</category><category>unifi</category><category>unifi-os</category><category>auth-bypass</category><category>path-traversal</category><category>command-injection</category><category>rce</category><category>unauth</category><category>kev</category><category>mirai</category><category>nginx</category><category>CVE-2026-34910</category></item><item><title>Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-15_cve-2026-47301-sccm-adminservice-cab-rce/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-15_cve-2026-47301-sccm-adminservice-cab-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-47301. Status: Patched. Affects: Microsoft Configuration Manager (SCCM / ConfigMgr), AdminService REST API. Tags: windows, sccm, configmgr, rce, cab, path-traversal, dll-hijacking, dll-proxy, arbitrary-file-write, system, microsoft, CVE-2026-47301.</description><category>network</category><category>Critical</category><category>windows</category><category>sccm</category><category>configmgr</category><category>rce</category><category>cab</category><category>path-traversal</category><category>dll-hijacking</category><category>dll-proxy</category><category>arbitrary-file-write</category><category>system</category><category>microsoft</category><category>CVE-2026-47301</category></item><item><title>Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-17106-copyescape-docker-cp-host-takeover/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-17106-copyescape-docker-cp-host-takeover/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-17106. Status: Patched. Affects: Docker Engine / Docker Desktop, docker cp CLI command. Tags: docker, container-escape, race-condition, symlink, path-traversal, runc, host-takeover, linux, macos, CWE-367, CWE-59, CVE-2026-17106.</description><category>binary</category><category>Critical</category><category>docker</category><category>container-escape</category><category>race-condition</category><category>symlink</category><category>path-traversal</category><category>runc</category><category>host-takeover</category><category>linux</category><category>macos</category><category>CWE-367</category><category>CWE-59</category><category>CVE-2026-17106</category></item><item><title>Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025). Status: Patched (Oracle out-of-band Security Alert, October 2025). Affects: Oracle E-Business Suite — Oracle Concurrent Processing product, BI Publisher Integration component (reached via the /OA_HTML/ web tier: configurator/UiServlet and ieshostedsurvey.jsp). Tags: oracle-ebs, oracle-concurrent-processing, bi-publisher-integration, pre-auth, rce, ssrf, crlf-injection, request-smuggling, path-traversal, auth-bypass, xslt, java, cisa-kev, ransomware, cl0p, watchtowr.</description><category>web</category><category>Critical</category><category>oracle-ebs</category><category>oracle-concurrent-processing</category><category>bi-publisher-integration</category><category>pre-auth</category><category>rce</category><category>ssrf</category><category>crlf-injection</category><category>request-smuggling</category><category>path-traversal</category><category>auth-bypass</category><category>xslt</category><category>java</category><category>cisa-kev</category><category>ransomware</category><category>cl0p</category><category>watchtowr</category></item><item><title>Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-65694-microweber-path-traversal/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-65694-microweber-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-65694 (VulnCheck advisory). Status: Unpatched. Affects: Microweber CMS — ServeStaticFileContoller::serveFromUserfiles(). Tags: microweber, path-traversal, cwe-22, unauthenticated, arbitrary-file-read, laravel, query-string-override.</description><category>web</category><category>High</category><category>microweber</category><category>path-traversal</category><category>cwe-22</category><category>unauthenticated</category><category>arbitrary-file-read</category><category>laravel</category><category>query-string-override</category></item><item><title>Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48282-coldfusion-rds-path-traversal-rce/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48282-coldfusion-rds-path-traversal-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48282 (Adobe APSB26-68). Status: Weaponized — arbitrary file read/write, directory browsing, webshell deployment, and command execution all confirmed. Affects: Adobe ColdFusion — Remote Development Service (RDS), /CFIDE/main/ide.cfm. Tags: coldfusion, adobe, rds, path-traversal, cwe-22, unauthenticated, remote, webshell, kev, actively-exploited.</description><category>web</category><category>Critical</category><category>coldfusion</category><category>adobe</category><category>rds</category><category>path-traversal</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>webshell</category><category>kev</category><category>actively-exploited</category></item><item><title>Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56260-crawl4ai-output-path-arbitrary-write/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56260-crawl4ai-output-path-arbitrary-write/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-56260 (GHSA-365w-hqf6-vxfg). Status: PoC — lab (vulnerable-app/) demonstrates genuine unrestricted arbitrary file write; the bundled poc.py scanner is deliberately conservative (writes only to a randomized safe /tmp marker) so it is safe to run against real/production targets. See Notes.. Affects: Crawl4AI — open-source LLM-friendly web crawler/scraper (unclecode/crawl4ai), Docker API server mode. Tags: crawl4ai, ai-web-crawler, docker-api, path-traversal, arbitrary-file-write, cwe-22, unauthenticated, remote, denial-of-service.</description><category>web</category><category>Critical</category><category>crawl4ai</category><category>ai-web-crawler</category><category>docker-api</category><category>path-traversal</category><category>arbitrary-file-write</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>denial-of-service</category></item><item><title>ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2023-38950-zkteco-biotime-path-traversal/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2023-38950-zkteco-biotime-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2023-38950. Status: Weaponized (public PoC, in CISA KEV). Affects: ZKTeco BioTime (web-based time &amp; attendance / access control management platform). Tags: zkteco, biotime, path-traversal, arbitrary-file-read, cwe-22, unauthenticated, remote, iclock-api, kev.</description><category>web</category><category>High</category><category>zkteco</category><category>biotime</category><category>path-traversal</category><category>arbitrary-file-read</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>iclock-api</category><category>kev</category></item><item><title>Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4632-magicinfo-path-traversal-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4632-magicinfo-path-traversal-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-4632. Status: Weaponized. Affects: Samsung MagicINFO 9 Server (digital signage content management server), SWUpdateFileUploader servlet. Tags: samsung, magicinfo, path-traversal, arbitrary-file-upload, unauthenticated-rce, jsp-webshell, cwe-22, cwe-434, python.</description><category>web</category><category>Critical</category><category>samsung</category><category>magicinfo</category><category>path-traversal</category><category>arbitrary-file-upload</category><category>unauthenticated-rce</category><category>jsp-webshell</category><category>cwe-22</category><category>cwe-434</category><category>python</category></item><item><title>Python tarfile `filter="data"` Bypass via PATH_MAX/realpath Confusion (CVE-2025-4517)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-06_cve-2025-4517-tarfile-filter-data-path-max-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-06_cve-2025-4517-tarfile-filter-data-path-max-bypass/</guid><description>Critical severity (CVSS 9.4) — misc · CVE-2025-4517. Status: Weaponized. Affects: Python standard library tarfile module — filter="data" / filter="tar" extraction filters (PEP 706). Tags: python, tarfile, path-traversal, sandbox-bypass, path_max, realpath, symlink, cwe-22, stdlib.</description><category>misc</category><category>Critical</category><category>python</category><category>tarfile</category><category>path-traversal</category><category>sandbox-bypass</category><category>path_max</category><category>realpath</category><category>symlink</category><category>cwe-22</category><category>stdlib</category></item><item><title>Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49132-pterodactyl-locale-path-traversal/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49132-pterodactyl-locale-path-traversal/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-49132. Status: Weaponized. Affects: Pterodactyl Panel (game server management panel). Tags: pterodactyl, path-traversal, unauthenticated, information-disclosure, credential-leak, database, php, config-exposure, cwe-22.</description><category>web</category><category>Critical</category><category>pterodactyl</category><category>path-traversal</category><category>unauthenticated</category><category>information-disclosure</category><category>credential-leak</category><category>database</category><category>php</category><category>config-exposure</category><category>cwe-22</category></item><item><title>Mitel MiCollab Path Normalization Bypass to Internal Endpoints (CVE-2025-52913)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-52913-mitel-micollab-path-traversal/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-52913-mitel-micollab-path-traversal/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-52913. Status: PoC. Affects: Mitel MiCollab (unified communications appliance). Tags: mitel, micollab, path-traversal, path-normalization, access-control-bypass, authentication-bypass, cwe-22, axis2, python, unified-communications.</description><category>network</category><category>Critical</category><category>mitel</category><category>micollab</category><category>path-traversal</category><category>path-normalization</category><category>access-control-bypass</category><category>authentication-bypass</category><category>cwe-22</category><category>axis2</category><category>python</category><category>unified-communications</category></item><item><title>FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-64446-fortiweb-cgiinfo-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-64446-fortiweb-cgiinfo-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-64446. Status: PoC. Affects: Fortinet FortiWeb (Web Application Firewall appliance). Tags: fortiweb, fortinet, waf, authentication-bypass, path-traversal, cgiinfo, cwe-22, cwe-288, admin-account-creation, python.</description><category>network</category><category>Critical</category><category>fortiweb</category><category>fortinet</category><category>waf</category><category>authentication-bypass</category><category>path-traversal</category><category>cgiinfo</category><category>cwe-22</category><category>cwe-288</category><category>admin-account-creation</category><category>python</category></item><item><title>Cisco ASA/FTD WebVPN File-Handler Heap Buffer Overflow Exposure Scanner (CVE-2025-20333)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-20333-cisco-asa-ftd-webvpn-buffer-overflow/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-20333-cisco-asa-ftd-webvpn-buffer-overflow/</guid><description>Critical severity (CVSS 9.9) — network · CVE-2025-20333. Status: PoC. Affects: Cisco Secure ASA and Cisco Secure FTD (WebVPN / AnyConnect file upload handler). Tags: cisco, asa, ftd, webvpn, anyconnect, heap-buffer-overflow, cwe-120, rce-as-root, exposure-scanner, path-traversal, python.</description><category>network</category><category>Critical</category><category>cisco</category><category>asa</category><category>ftd</category><category>webvpn</category><category>anyconnect</category><category>heap-buffer-overflow</category><category>cwe-120</category><category>rce-as-root</category><category>exposure-scanner</category><category>path-traversal</category><category>python</category></item><item><title>ZimaOS Arbitrary File Write via Unvalidated File API Path — CVE-2026-28286</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-28286-zimaos-arbitrary-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-28286-zimaos-arbitrary-file-write/</guid><description>Critical severity — web · CVE-2026-28286. Status: PoC. Affects: ZimaOS (NAS / home-server operating system), file API endpoint /v2_1/files/file. Tags: zimaos, nas, arbitrary-file-write, path-traversal, api-misconfiguration, rce, home-server.</description><category>web</category><category>Critical</category><category>zimaos</category><category>nas</category><category>arbitrary-file-write</category><category>path-traversal</category><category>api-misconfiguration</category><category>rce</category><category>home-server</category></item><item><title>WPvivid Backup &amp; Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1357-wpvivid-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1357-wpvivid-file-upload-rce/</guid><description>Critical severity — web · CVE-2026-1357. Status: Weaponized. Affects: WPvivid Backup &amp; Migration WordPress plugin. Tags: wordpress, wpvivid, arbitrary-file-upload, rce, unauthenticated, cryptography, path-traversal.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wpvivid</category><category>arbitrary-file-upload</category><category>rce</category><category>unauthenticated</category><category>cryptography</category><category>path-traversal</category></item><item><title>Veno File Manager Path Traversal to Arbitrary File Read (CVE-2026-37066)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37066-veno-file-manager-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37066-veno-file-manager-path-traversal/</guid><description>High severity — web · CVE-2026-37066. Status: PoC. Affects: Veno File Manager Project. Tags: veno-file-manager, path-traversal, arbitrary-file-read, authenticated, superadmin, cwe-22.</description><category>web</category><category>High</category><category>veno-file-manager</category><category>path-traversal</category><category>arbitrary-file-read</category><category>authenticated</category><category>superadmin</category><category>cwe-22</category></item><item><title>UnPoller Path Traversal / Arbitrary File Read via file:// Password Prefix (CVE-2026-36851)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-36851-unpoller-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-36851-unpoller-path-traversal/</guid><description>High severity (CVSS 7.5) — misc · CVE-2026-36851. Status: PoC. Affects: UnPoller (unpoller/unpoller). Tags: unpoller, path-traversal, arbitrary-file-read, unifi, cwe-22, cwe-20.</description><category>misc</category><category>High</category><category>unpoller</category><category>path-traversal</category><category>arbitrary-file-read</category><category>unifi</category><category>cwe-22</category><category>cwe-20</category></item><item><title>TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-0651-tapo-c260-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-0651-tapo-c260-rce/</guid><description>Critical severity — network · CVE-2026-0651 (chained with CVE-2026-0652, CVE-2026-0653). Status: Weaponized. Affects: TP-Link Tapo C260 IP camera (pre-patch firmware, shared /bin/main omnibus binary across models). Tags: iot, ip-camera, tp-link, tapo, path-traversal, command-injection, privilege-escalation, exploit-chain.</description><category>network</category><category>Critical</category><category>iot</category><category>ip-camera</category><category>tp-link</category><category>tapo</category><category>path-traversal</category><category>command-injection</category><category>privilege-escalation</category><category>exploit-chain</category></item><item><title>Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25964-tandoor-recipes-lfi/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25964-tandoor-recipes-lfi/</guid><description>Medium severity (CVSS 4.9) — web · CVE-2026-25964 (GHSA-6485-jr28-52xx). Status: PoC. Affects: Tandoor Recipes (self-hosted recipe manager, Django-based). Tags: path-traversal, local-file-disclosure, tandoor-recipes, django, rest-api, authenticated, cwe-22, arbitrary-file-read.</description><category>web</category><category>Medium</category><category>path-traversal</category><category>local-file-disclosure</category><category>tandoor-recipes</category><category>django</category><category>rest-api</category><category>authenticated</category><category>cwe-22</category><category>arbitrary-file-read</category></item><item><title>Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1056-snow-monkey-forms-file-deletion/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1056-snow-monkey-forms-file-deletion/</guid><description>Critical severity — web · CVE-2026-1056. Status: PoC. Affects: Snow Monkey Forms (WordPress plugin). Tags: wordpress, plugin, snow-monkey-forms, path-traversal, file-deletion, unauthenticated, rest-api, csrf-bypass.</description><category>web</category><category>Critical</category><category>wordpress</category><category>plugin</category><category>snow-monkey-forms</category><category>path-traversal</category><category>file-deletion</category><category>unauthenticated</category><category>rest-api</category><category>csrf-bypass</category></item><item><title>Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-11912-simple-file-list-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-11912-simple-file-list-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-11912. Status: PoC. Affects: Simple File List WordPress plugin. Tags: wordpress, plugin, path-traversal, missing-authorization, unauthenticated, file-deletion, ajax, nonce.</description><category>web</category><category>High</category><category>wordpress</category><category>plugin</category><category>path-traversal</category><category>missing-authorization</category><category>unauthenticated</category><category>file-deletion</category><category>ajax</category><category>nonce</category></item><item><title>Perfmatters WordPress Plugin Arbitrary File Deletion (CVE-2026-4350)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4350-perfmatters-file-deletion/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4350-perfmatters-file-deletion/</guid><description>High severity (CVSS 8.1) — web · CVE-2026-4350. Status: PoC. Affects: Perfmatters WordPress plugin. Tags: wordpress, plugin, perfmatters, path-traversal, arbitrary-file-deletion, admin-ajax, dos, nuclei.</description><category>web</category><category>High</category><category>wordpress</category><category>plugin</category><category>perfmatters</category><category>path-traversal</category><category>arbitrary-file-deletion</category><category>admin-ajax</category><category>dos</category><category>nuclei</category></item><item><title>OpenPLC_v3 glue_generator Path Traversal — CVE-2026-31156</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-31156-openplc-glue-generator-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-05_cve-2026-31156-openplc-glue-generator-traversal/</guid><description>High severity — hardware · CVE-2026-31156. Status: PoC. Affects: OpenPLC_v3 — utils/glue_generator_src/glue_generator.cpp build/code-generation utility. Tags: openplc, ics, path-traversal, arbitrary-file-write, glue-generator, cpp, plc, industrial-control.</description><category>hardware</category><category>High</category><category>openplc</category><category>ics</category><category>path-traversal</category><category>arbitrary-file-write</category><category>glue-generator</category><category>cpp</category><category>plc</category><category>industrial-control</category></item><item><title>OpenEMR EtherFax Module Authenticated Arbitrary File Read (CVE-2026-24849)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24849-openemr-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24849-openemr-path-traversal/</guid><description>Critical severity (CVSS 6.5) — web · CVE-2026-24849. Status: PoC. Affects: OpenEMR (Fax/SMS module, EtherFax provider). Tags: openemr, path-traversal, arbitrary-file-read, cwe-22, php, healthcare, phi-exposure, authenticated.</description><category>web</category><category>Critical</category><category>openemr</category><category>path-traversal</category><category>arbitrary-file-read</category><category>cwe-22</category><category>php</category><category>healthcare</category><category>phi-exposure</category><category>authenticated</category></item><item><title>Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-29786-node-tar-symlink-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-29786-node-tar-symlink-traversal/</guid><description>High severity — misc · CVE-2026-29786. Status: PoC. Affects: tar npm package (Node.js). Tags: node-tar, path-traversal, symlink, archive-extraction, arbitrary-file-write, nodejs, supply-chain.</description><category>misc</category><category>High</category><category>node-tar</category><category>path-traversal</category><category>symlink</category><category>archive-extraction</category><category>arbitrary-file-write</category><category>nodejs</category><category>supply-chain</category></item><item><title>node-tar Hardlink/Symlink Path Traversal Arbitrary File Overwrite (CVE-2026-23745)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23745-node-tar-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-23745-node-tar-path-traversal/</guid><description>High severity — misc · CVE-2026-23745 / GHSA-8qq5-rm4j-mr97. Status: PoC. Affects: node-tar (npm package tar). Tags: node-tar, path-traversal, arbitrary-file-overwrite, hardlink, symlink, supply-chain, nodejs, tar-archive.</description><category>misc</category><category>High</category><category>node-tar</category><category>path-traversal</category><category>arbitrary-file-overwrite</category><category>hardlink</category><category>symlink</category><category>supply-chain</category><category>nodejs</category><category>tar-archive</category></item><item><title>Nezha Dashboard Path Traversal → JWT Secret Leak → Token Forgery — CVE-2026-53519</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-53519-nezha-path-traversal-jwt-forgery/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-53519-nezha-path-traversal-jwt-forgery/</guid><description>Info severity — web · CVE-2026-53519 (GHSA-5c25-7vpj-9mqh). Status: PoC. Affects: Nezha Dashboard (monitoring/agent management panel). Tags: nezha, path-traversal, jwt-forgery, unauthenticated, config-disclosure, sqlite, privilege-escalation, cwe-22, cwe-347.</description><category>web</category><category>Info</category><category>nezha</category><category>path-traversal</category><category>jwt-forgery</category><category>unauthenticated</category><category>config-disclosure</category><category>sqlite</category><category>privilege-escalation</category><category>cwe-22</category><category>cwe-347</category></item><item><title>MindsDB — Handler Path Traversal to Remote Code Execution (CVE-2026-27483)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27483-mindsdb-path-traversal-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27483-mindsdb-path-traversal-rce/</guid><description>Critical severity — web · CVE-2026-27483. Status: Weaponized. Affects: MindsDB (version observed: 25.9.1.0). Tags: mindsdb, path-traversal, rce, reverse-shell, unauthenticated, pip-overwrite, python.</description><category>web</category><category>Critical</category><category>mindsdb</category><category>path-traversal</category><category>rce</category><category>reverse-shell</category><category>unauthenticated</category><category>pip-overwrite</category><category>python</category></item><item><title>mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27825-mcp-atlassian-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27825-mcp-atlassian-path-traversal/</guid><description>Critical severity (CVSS 9.3) — web · CVE-2026-27825 (read-side twin of GHSA-xjgw-4wvw-rgm4). Status: PoC. Affects: sooperset/mcp-atlassian MCP server. Tags: mcp, path-traversal, arbitrary-file-read, confluence, mcp-atlassian, cwe-22, unauthenticated.</description><category>web</category><category>Critical</category><category>mcp</category><category>path-traversal</category><category>arbitrary-file-read</category><category>confluence</category><category>mcp-atlassian</category><category>cwe-22</category><category>unauthenticated</category></item><item><title>LiquidJS Template Engine Path Traversal — CVE-2026-30952</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-30952-liquidjs-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-30952-liquidjs-path-traversal/</guid><description>High severity (CVSS 8.7) — misc · CVE-2026-30952 (GHSA-wmfp-5q7x-987x). Status: PoC. Affects: liquidjs npm package (LiquidJS template engine). Tags: liquidjs, path-traversal, template-engine, arbitrary-file-read, nodejs, library, ssti-adjacent.</description><category>misc</category><category>High</category><category>liquidjs</category><category>path-traversal</category><category>template-engine</category><category>arbitrary-file-read</category><category>nodejs</category><category>library</category><category>ssti-adjacent</category></item><item><title>Langflow Knowledge Base Path Traversal / Arbitrary Directory Deletion (CVE-2026-42048)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42048-langflow-kb-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-42048-langflow-kb-path-traversal/</guid><description>High severity — web · CVE-2026-42048 (GHSA-9whx-c884-c68q). Status: PoC. Affects: Langflow (Knowledge Bases bulk delete API). Tags: langflow, path-traversal, arbitrary-file-deletion, cwe-22, api, docker-lab, knowledge-base.</description><category>web</category><category>High</category><category>langflow</category><category>path-traversal</category><category>arbitrary-file-deletion</category><category>cwe-22</category><category>api</category><category>docker-lab</category><category>knowledge-base</category></item><item><title>iOS App Intents Path Traversal — CVE-2026-28995</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-28995-ios-appintents-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-28995-ios-appintents-path-traversal/</guid><description>High severity — misc · CVE-2026-28995. Status: PoC. Affects: Apple App Intents framework (iOS). Tags: ios, app-intents, path-traversal, sandbox-escape, swift, file-disclosure, mobile.</description><category>misc</category><category>High</category><category>ios</category><category>app-intents</category><category>path-traversal</category><category>sandbox-escape</category><category>swift</category><category>file-disclosure</category><category>mobile</category></item><item><title>InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23491-invoiceplane-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23491-invoiceplane-path-traversal/</guid><description>Critical severity — web · CVE-2026-23491. Status: PoC. Affects: InvoicePlane. Tags: invoiceplane, path-traversal, directory-traversal, unauthenticated, information-disclosure, php, arbitrary-file-read.</description><category>web</category><category>Critical</category><category>invoiceplane</category><category>path-traversal</category><category>directory-traversal</category><category>unauthenticated</category><category>information-disclosure</category><category>php</category><category>arbitrary-file-read</category></item><item><title>Gravity Forms Path Traversal → Arbitrary File Deletion (CVE-2026-48866)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48866-gravityforms-path-traversal-file-deletion/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48866-gravityforms-path-traversal-file-deletion/</guid><description>Critical severity (CVSS 9.6) — web · CVE-2026-48866. Status: PoC. Affects: Gravity Forms plugin for WordPress. Tags: wordpress, gravity-forms, path-traversal, cwe-22, arbitrary-file-deletion, php, unauthenticated-injection.</description><category>web</category><category>Critical</category><category>wordpress</category><category>gravity-forms</category><category>path-traversal</category><category>cwe-22</category><category>arbitrary-file-deletion</category><category>php</category><category>unauthenticated-injection</category></item><item><title>Gogs Wiki Arbitrary File Deletion via Path Traversal (CVE-2026-24135)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24135-gogs-wiki-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24135-gogs-wiki-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-24135 (GHSA-jp7c-wj6q-3qf2). Status: PoC. Affects: Gogs self-hosted Git service. Tags: gogs, path-traversal, arbitrary-file-deletion, wiki, git-service, authenticated, go.</description><category>web</category><category>High</category><category>gogs</category><category>path-traversal</category><category>arbitrary-file-deletion</category><category>wiki</category><category>git-service</category><category>authenticated</category><category>go</category></item><item><title>Gogs Organization-Name Path Traversal to RCE via Git Hooks — CVE-2026-52813</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-52813-gogs-path-traversal-hook-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-52813-gogs-path-traversal-hook-rce/</guid><description>Info severity — web · CVE-2026-52813. Status: PoC. Affects: Gogs (self-hosted Git service), organization creation feature. Tags: gogs, path-traversal, git-hooks, rce, authenticated, account-takeover, self-hosted-git.</description><category>web</category><category>Info</category><category>gogs</category><category>path-traversal</category><category>git-hooks</category><category>rce</category><category>authenticated</category><category>account-takeover</category><category>self-hosted-git</category></item><item><title>FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25895-fuxa-path-traversal-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25895-fuxa-path-traversal-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-25895. Status: Weaponized. Affects: FUXA (Node.js-based SCADA/HMI platform), frangoteam. Tags: fuxa, scada, ics, path-traversal, arbitrary-file-write, rce, unauthenticated, cwe-22, cron-persistence, webshell.</description><category>web</category><category>Critical</category><category>fuxa</category><category>scada</category><category>ics</category><category>path-traversal</category><category>arbitrary-file-write</category><category>rce</category><category>unauthenticated</category><category>cwe-22</category><category>cron-persistence</category><category>webshell</category></item><item><title>EspoCRM Authenticated RCE via Formula ACL Bypass + Attachment Path Traversal — CVE-2026-33656</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33656-espocrm-formula-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33656-espocrm-formula-rce/</guid><description>Critical severity — web · CVE-2026-33656. Status: Weaponized. Affects: EspoCRM &lt;= 9.3.3. Tags: espocrm, rce, path-traversal, webshell, htaccess-poisoning, formula-engine, authenticated, crm.</description><category>web</category><category>Critical</category><category>espocrm</category><category>rce</category><category>path-traversal</category><category>webshell</category><category>htaccess-poisoning</category><category>formula-engine</category><category>authenticated</category><category>crm</category></item><item><title>Centreon Multi-Vector RCE — Path Traversal, Command Injection &amp; Blind SQLi (CVE-2026-2749)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-2749-centreon-multi-vector-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-2749-centreon-multi-vector-rce/</guid><description>Critical severity — web · CVE-2026-2749 (bundled with related CVE-2026-2750, CVE-2026-2751). Status: Weaponized. Affects: Centreon (open-source IT infrastructure monitoring platform). Tags: centreon, path-traversal, rce, command-injection, sql-injection, clapi, monitoring, php.</description><category>web</category><category>Critical</category><category>centreon</category><category>path-traversal</category><category>rce</category><category>command-injection</category><category>sql-injection</category><category>clapi</category><category>monitoring</category><category>php</category></item><item><title>Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6815-casdoor-path-traversal-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6815-casdoor-path-traversal-file-write/</guid><description>High severity — web · CVE-2026-6815. Status: Weaponized. Affects: Casdoor (open-source identity/access management platform). Tags: casdoor, path-traversal, arbitrary-file-write, rce, dos, authenticated, cwe-22.</description><category>web</category><category>High</category><category>casdoor</category><category>path-traversal</category><category>arbitrary-file-write</category><category>rce</category><category>dos</category><category>authenticated</category><category>cwe-22</category></item><item><title>BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39387-boidcms-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39387-boidcms-file-upload-rce/</guid><description>High severity — web · CVE-2026-39387. Status: Weaponized. Affects: BoidCMS. Tags: boidcms, php, authenticated, file-upload, path-traversal, template-injection, rce.</description><category>web</category><category>High</category><category>boidcms</category><category>php</category><category>authenticated</category><category>file-upload</category><category>path-traversal</category><category>template-injection</category><category>rce</category></item><item><title>BetterDocs Pro Unauthenticated Local File Inclusion to RCE — CVE-2026-7515</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-7515-poc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-7515-poc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-7515. Status: PoC. Affects: BetterDocs Pro (WordPress plugin). Tags: wordpress, betterdocs-pro, lfi, path-traversal, log-poisoning, rce, cwe-98, admin-ajax.</description><category>web</category><category>Critical</category><category>wordpress</category><category>betterdocs-pro</category><category>lfi</category><category>path-traversal</category><category>log-poisoning</category><category>rce</category><category>cwe-98</category><category>admin-ajax</category></item><item><title>ApostropheCMS Import — Malicious Tar Archive Path Traversal (CVE-2026-32731)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-32731-apostrophecms-tar-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-32731-apostrophecms-tar-path-traversal/</guid><description>High severity — web · CVE-2026-32731. Status: PoC. Affects: ApostropheCMS (site export/import feature). Tags: apostrophecms, cms, path-traversal, tar-slip, arbitrary-file-write, import, node-js.</description><category>web</category><category>High</category><category>apostrophecms</category><category>cms</category><category>path-traversal</category><category>tar-slip</category><category>arbitrary-file-write</category><category>import</category><category>node-js</category></item><item><title>Apktool Resource Table Path Traversal — Malicious APK Builder (CVE-2026-39973)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-39973-apktool-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-39973-apktool-path-traversal/</guid><description>High severity — misc · CVE-2026-39973. Status: PoC. Affects: iBotPeaches/Apktool (Android APK decompiler/rebuilder). Tags: apktool, path-traversal, resources-arsc, apk, decompilation, arbitrary-file-write, android-tooling.</description><category>misc</category><category>High</category><category>apktool</category><category>path-traversal</category><category>resources-arsc</category><category>apk</category><category>decompilation</category><category>arbitrary-file-write</category><category>android-tooling</category></item><item><title>AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21440-adonisjs-bodyparser-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21440-adonisjs-bodyparser-path-traversal/</guid><description>Critical severity (CVSS 9.2) — web · CVE-2026-21440 (GHSA-gvq6-hvvp-h34h). Status: Weaponized. Affects: @adonisjs/bodyparser (AdonisJS multipart file-upload handling). Tags: adonisjs, nodejs, path-traversal, arbitrary-file-write, cwe-22, file-upload, rce, bodyparser.</description><category>web</category><category>Critical</category><category>adonisjs</category><category>nodejs</category><category>path-traversal</category><category>arbitrary-file-write</category><category>cwe-22</category><category>file-upload</category><category>rce</category><category>bodyparser</category></item><item><title>Docker cp Copy-Out Destination Escape via Symlink Race</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-03_docker-cp-copyout-destination-escape/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-03_docker-cp-copyout-destination-escape/</guid><description>Medium severity — cloud · None assigned as of 2026-07-03. Status: PoC. Affects: Docker Engine / CLI. Tags: docker, container-escape, toctou, symlink-race, docker-cp, path-traversal, archive-extraction, host-file-write.</description><category>cloud</category><category>Medium</category><category>docker</category><category>container-escape</category><category>toctou</category><category>symlink-race</category><category>docker-cp</category><category>path-traversal</category><category>archive-extraction</category><category>host-file-write</category></item><item><title>WinRAR Windows Path Traversal via NTFS Alternate Data Streams (CVE-2025-8088)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-01_cve-2025-8088-winrar-ads-path-traversal/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-01_cve-2025-8088-winrar-ads-path-traversal/</guid><description>High severity (CVSS 8.4) — misc · CVE-2025-8088. Status: Weaponized. Affects: WinRAR (Windows). Tags: path-traversal, WinRAR, NTFS, Alternate-Data-Streams, RomCom, Storm-0978, persistence, startup-folder, in-the-wild.</description><category>misc</category><category>High</category><category>path-traversal</category><category>WinRAR</category><category>NTFS</category><category>Alternate-Data-Streams</category><category>RomCom</category><category>Storm-0978</category><category>persistence</category><category>startup-folder</category><category>in-the-wild</category></item><item><title>Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-20262-cisco-sdwan-manager-file-write/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-20262-cisco-sdwan-manager-file-write/</guid><description>Medium severity (CVSS 6.5) — network · CVE-2026-20262. Status: PoC. Affects: Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). Tags: path-traversal, file-write, Cisco, SD-WAN, vManage, authenticated, CWE-22, active-exploitation.</description><category>network</category><category>Medium</category><category>path-traversal</category><category>file-write</category><category>Cisco</category><category>SD-WAN</category><category>vManage</category><category>authenticated</category><category>CWE-22</category><category>active-exploitation</category></item><item><title>Ubiquiti UniFi OS Unauthenticated RCE Chain (CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-34908-unifi-os-rce-chain/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-34908-unifi-os-rce-chain/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-34908, CVE-2026-34909, CVE-2026-34910. Status: PoC. Affects: Ubiquiti UniFi OS Server. Tags: unauth-rce, nginx-bypass, path-traversal, command-injection, CISA-KEV, Mirai, Gaafgyt, chain, UniFi, Ubiquiti, network.</description><category>network</category><category>Critical</category><category>unauth-rce</category><category>nginx-bypass</category><category>path-traversal</category><category>command-injection</category><category>CISA-KEV</category><category>Mirai</category><category>Gaafgyt</category><category>chain</category><category>UniFi</category><category>Ubiquiti</category><category>network</category></item></channel></rss>