PT-2026-69852 · Opencart · Opencart

CVE-2026-18412

·

Published

2026-08-10

·

Updated

2026-08-12

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenCart version 4.2.0.0
Description The extension installer fails to validate that extracted paths from uploaded .ocmod.zip files remain within the intended directory. This allows an attacker to use directory traversal sequences, such as ../, to write arbitrary files, including PHP web shells, directly into the webroot directory.
Recommendations Update OpenCart version 4.2.0.0 to a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-18412

Affected Products

Opencart