PT-2026-50550 · Cakephp · Cakephp

·

CVE-2026-48820

·

Published

2026-06-17

·

Updated

2026-06-26

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CakePHP versions prior to 4.5.11 CakePHP versions 4.6.0 through 4.6.3 CakePHP versions 5.0.0 through 5.1.6 CakePHP versions 5.2.0 through 5.2.12 CakePHP versions 5.3.0 through 5.3.5
Description The getElementFileName() function in the View class does not verify that the resolved element path remains within the application or plugin view template paths. If element names are constructed using specially crafted user-supplied data, this can be exploited to include arbitrary PHP files from the server.
Recommendations Update to version 4.5.11 Update to version 4.6.4 Update to version 5.1.7 Update to version 5.2.13 Update to version 5.3.6

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48820
GHSA-WPVJ-HJCR-H3P2

Affected Products

Cakephp