Skip to content
Threat Feed
high advisory

Path Traversal Vulnerability in Formwork BackupController

Formwork prior to version 2.3.13 contains a path traversal vulnerability in the BackupController component allowing authenticated users to read or delete arbitrary files via base64-encoded payloads.

CVE search metadata

CVE search record: CVE-2026-104478. Severity: high. CVSS: 7.1. KEV: no. Product: Formwork (< 2.3.13). Brief: Path Traversal Vulnerability in Formwork BackupController. Brief link: https://feed.craftedsignal.io/briefs/2026-10-formwork-path-traversal/

Formwork versions prior to 2.3.13 are vulnerable to a path traversal vulnerability residing within the BackupController component. This vulnerability allows authenticated users who possess backup download or deletion permissions to escape the intended directory structure. By providing a base64-encoded, backslash-separated payload, an attacker can bypass the PHP basename validation logic on Linux-based installations. Successful exploitation permits an authenticated attacker to read sensitive configuration files or delete critical system files, potentially leading to full system compromise or service disruption. Defenders should prioritize updating to version 2.3.13 or later to remediate the underlying flaw in file handling.

Impact

Successful exploitation of CVE-2026-104478 allows an authenticated user to perform arbitrary file reads or deletions. This impacts the integrity and confidentiality of the Formwork installation and underlying server data. If the service is running with elevated privileges, the impact can extend to the broader system environment.

Recommendation

  • Upgrade Formwork to version 2.3.13 or later immediately to patch CVE-2026-104478.
  • Review access control lists for the administrative panel and restrict backup download and delete permissions to only the most trusted administrative accounts.
  • Audit web server access logs for requests to the BackupController endpoint that contain unusual, encoded, or backslash-heavy string patterns.

Immediate actions

Upgrade Formwork to version 2.3.13

IT Operations 48h

Mitigations

Upgrade to 2.3.13

immediate IT Operations

CVE-2026-104478