PT-2026-72074 · Emlog · Emlog

CVE-2026-73849

·

Published

2026-08-14

·

Updated

2026-08-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emlog versions prior to 2.6.27
Description The install.php endpoint allows the action parameter to be set to reinstall without authentication. This bypasses the installation check because the security guard only executes when the $act variable is not equal to reinstall. A remote attacker can provide values for hostname, dbuser, dbpasswd, dbname, dbprefix, username, password, and email to trigger the file put contents() function. This allows the attacker to overwrite the config.php file with malicious database settings and create a new administrator account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73849
GHSA-V5QQ-P8MP-3GXM

Affected Products

Emlog