PT-2026-56903 · Unknown · Librebooking

·

CVE-2026-61343

·

Published

2026-07-09

·

Updated

2026-07-13

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LibreBooking versions prior to 5.1.0
Description The email template editor save action allows a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. This occurs because the submitted template name is passed directly into the destination file path.
Recommendations Update to version 5.1.0.

Exploit

Fix

RCE

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61343

Affected Products

Librebooking