PT-2026-95089 · Wavelog · Wavelog

·

CVE-2026-54237

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Wavelog versions 1.8 through 2.4.1
Description Wavelog exposes the endpoints '/install/ajax.php' and '/install/includes/interface assets/triggers.php' after installation without requiring an installation lock or permission check. Unsanitized input reaches the functions write config() and write configfile() in install/includes/core/core class.php, enabling a remote unauthenticated attacker to read or write log files and insert controlled content into PHP configuration files, which can lead to remote code execution on the server.
Recommendations Update to version 2.4.2.

Exploit

Fix

Code Injection

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54237
GHSA-JXJV-CHGM-RH36

Affected Products

Wavelog