PT-2026-99393 · Unknown · Acymailing Enterprise

CVE-2026-94131

·

Published

2026-09-26

·

Updated

2026-09-29

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AcyMailing Enterprise versions prior to 11.1.0
Description An unauthenticated arbitrary file deletion issue exists where a subscriber can store a file path within a file-type custom field. When this field is cleared, the system may delete the specified file, potentially affecting files outside the designated upload folder, such as configuration.php.
Recommendations Update AcyMailing Enterprise to version 11.1.0 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94131

Affected Products

Acymailing Enterprise