{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/icecoder--8.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:icecoder:icecoder:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-64836"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ICEcoder (\u003c= 8.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ICEcoder"],"content_html":"\u003cp\u003eCVE-2026-64836 is a path traversal vulnerability affecting ICEcoder up to and including version 8.1. The flaw exists within the file-control endpoint, specifically due to a logic error in the File::check() validation function. This function attempts to verify that requested file paths remain within the defined document root by comparing realpath() results to boolean true, a comparison that consistently fails. As a result, the confinement check is bypassed. An authenticated attacker can exploit this by submitting traversal sequences (e.g., ../) or absolute paths in the file parameter. Successful exploitation allows for the reading, writing, or deletion of sensitive files on the underlying filesystem, potentially leading to remote code execution or complete system compromise. Organizations running these versions should restrict access to the file-control endpoint or upgrade to a remediated version once available.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains authenticated access to the ICEcoder web interface.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the file-control endpoint as a target for file interaction.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting the file parameter.\u003c/li\u003e\n\u003cli\u003eAttacker inserts directory traversal sequences or absolute file paths into the file parameter.\u003c/li\u003e\n\u003cli\u003eThe server-side File::check() function executes but fails to properly validate the input due to the logic error.\u003c/li\u003e\n\u003cli\u003eThe application processes the request, applying the operation (read, write, or delete) to the targeted file path.\u003c/li\u003e\n\u003cli\u003eAttacker achieves unauthorized file access, modification, or destruction outside the intended document root.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers to escape the application's document root, leading to unauthorized access to sensitive configuration files, source code, or system binaries. Depending on the environment, an attacker could delete essential system files or write malicious web shells to attain remote code execution, threatening the integrity and availability of the host server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rule below to monitor for suspicious path traversal patterns in web server logs targeting the ICEcoder file-control endpoint.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the ICEcoder instance to trusted IP ranges only.\u003c/li\u003e\n\u003cli\u003eMonitor file system integrity for modifications in directories outside the intended ICEcoder web root.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T15:09:34Z","date_published":"2026-09-10T15:09:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-icecoder-path-traversal/","summary":"ICEcoder versions 8.1 and earlier are vulnerable to path traversal via a logic error in the file-control endpoint, enabling authenticated attackers to perform arbitrary file reads, writes, and deletions.","title":"Path Traversal Vulnerability in ICEcoder (CVE-2026-64836)","url":"https://feed.craftedsignal.io/briefs/2026-09-icecoder-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - ICEcoder (\u003c= 8.1)","version":"https://jsonfeed.org/version/1.1"}