Sceawere
Vulnerability Detail
CVE-2026-55231UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Vvveb Arbitrary File System Access
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 1d ago
- Vendor
- givanz
- Product
- Vvveb
- Attack Type
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel user who holds backup access (default role site_admin or higher) read and delete arbitrary files on a server. An attacker can recover database credentials from config/db.php, read host files such as /etc/passwd, and delete config/db.php to push a site back into install mode for a full takeover. This issue has been patched in version 1.0.8.6.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-01T19:17:21.680Z",
"pubdate": "2026-10-01T19:17:21.680Z",
"executiveSummary": "The vulnerability identified in Vvveb, existing in versions prior to 1.0.8.6, involves a critical flaw in the central path sanitization mechanism. This security oversight permits authenticated users with administrative privileges, specifically those with backup access, to perform unauthorized file system operations.\nThe vulnerability is classified as an Arbitrary File Read and Delete issue. By exploiting the inadequate input validation of file paths, an attacker can bypass intended directory restrictions to interact with sensitive system files and application configuration files.\nThe impact of this vulnerability is severe, as it enables the extraction of sensitive credentials, such as database passwords stored in config/db.php, and permits the deletion of critical application files. Successful exploitation effectively compromises the confidentiality and availability of the server and the hosted application.\nThe attack is limited to authenticated users possessing at least site_admin roles; however, once inside the administrative panel, the attacker possesses sufficient privilege to execute these operations. The primary risk is total site takeover, where the deletion of configuration files can force the CMS into a re-installation state, allowing the attacker to re-initialize the application and gain full administrative control.\nThe vulnerability is remediated in version 1.0.8.6, and immediate application of this update is required for all affected instances.",
"technicalDetails": "The root cause of this vulnerability lies in the implementation of the central path sanitizer, which fails to correctly normalize or restrict file path inputs provided by administrative users. In Vvveb, the CMS utilizes a centralized handling mechanism for file system interactions, particularly within backup and file management modules. The sanitization logic is insufficient to prevent directory traversal or the referencing of files outside of the intended application directories.\nThe vulnerability is exploitable by an authenticated user with 'site_admin' privileges or higher. The attack vector involves submitting crafted file paths to the application functions responsible for reading or deleting files. Because the path sanitizer does not effectively validate the canonical path of the requested input, an attacker can utilize path traversal sequences (such as ../) to escape the web root and target arbitrary files on the underlying operating system.\nThe attack flow proceeds as follows: First, the attacker authenticates into the Vvveb admin panel using an account with sufficient privileges. Second, the attacker interacts with the file management or backup interface, injecting malicious paths into the file request parameters. Third, the application's flawed sanitization routine accepts these paths, mapping them to sensitive locations on the server.\nSpecific payloads demonstrate the ability to read system-level configuration, such as 'config/db.php', which contains database credentials, or sensitive system files such as '/etc/passwd'. Furthermore, the application's file deletion functionality can be leveraged to remove 'config/db.php'. By removing this critical configuration file, the application detects an unconfigured state upon the next execution request and reverts to the installation initialization flow. This allows the attacker to complete the setup process as an unauthorized user, thereby achieving a full administrative takeover of the CMS and the underlying database.\nThis vulnerability highlights a critical lack of input validation and path isolation, exposing the application to significant risks if an administrative account is compromised or if an insider threat exists. The failure to apply strict allow-listing for file system access paths is the primary architectural weakness leading to this exposure."
}