{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/microweber-cms/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-65694"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Microweber CMS"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","path-traversal","cms","webserver"],"_cs_type":"advisory","_cs_vendors":["Microweber"],"content_html":"\u003cp\u003eA critical path traversal vulnerability, tracked as CVE-2026-65694, has been identified in Microweber CMS versions up to and including 2.0.20. This flaw resides within the static file controller, specifically due to the \u003ccode\u003enormalize_path()\u003c/code\u003e function's failure to properly sanitize or strip directory traversal sequences provided in the \u003ccode\u003epath\u003c/code\u003e query parameter of HTTP GET requests. Unauthenticated remote attackers can leverage this vulnerability to bypass intended access controls and read arbitrary files on the server. Exploitation requires only a single unauthenticated HTTP GET request, making it highly accessible to attackers. Successful exploitation can lead to the disclosure of sensitive data, such as environment configuration files that often contain database credentials, API keys, or other confidential information, as well as critical system files. This poses a significant risk for data breaches and further system compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a vulnerable Microweber CMS instance (version 2.0.20 or earlier).\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET request targeting a web endpoint associated with the static file controller.\u003c/li\u003e\n\u003cli\u003eThe request includes a specially crafted \u003ccode\u003epath\u003c/code\u003e query parameter containing directory traversal sequences (e.g., \u003ccode\u003e../../\u003c/code\u003e) to navigate outside the intended directory.\u003c/li\u003e\n\u003cli\u003eThe vulnerable \u003ccode\u003enormalize_path()\u003c/code\u003e function within the CMS fails to properly remove these traversal sequences.\u003c/li\u003e\n\u003cli\u003eThe server processes the request, mistakenly resolving the path to an arbitrary file on the underlying operating system.\u003c/li\u003e\n\u003cli\u003eThe web server retrieves the content of the specified arbitrary file, such as \u003ccode\u003e/etc/passwd\u003c/code\u003e, \u003ccode\u003e/etc/shadow\u003c/code\u003e, or environment configuration files (\u003ccode\u003e.env\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe server includes the sensitive file's content in the HTTP response body to the attacker.\u003c/li\u003e\n\u003cli\u003eThe attacker successfully exfiltrates sensitive information, potentially leading to credential compromise or further system access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-65694 allows unauthenticated attackers to read any file accessible to the web server process. This directly leads to the disclosure of sensitive information such as database credentials, API keys, private configuration data, and system files. The impact could range from unauthorized access to sensitive application data to full system compromise if credentials for higher-privileged services are exposed. While no specific victim count or sectors are mentioned, any organization utilizing Microweber CMS versions affected by this vulnerability is at risk. Data breaches, intellectual property theft, and subsequent lateral movement or persistent access are potential consequences.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-65694 immediately by upgrading Microweber CMS to a version beyond 2.0.20 that addresses this vulnerability.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-65694 Exploitation - Microweber Path Traversal\u0026quot; to your SIEM to identify attempted exploitation.\u003c/li\u003e\n\u003cli\u003eEnsure web server logs (logsource category \u003ccode\u003ewebserver\u003c/code\u003e) are collected and ingested into your SIEM for effective detection.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to block HTTP GET requests containing directory traversal sequences (\u003ccode\u003e../\u003c/code\u003e, \u003ccode\u003e%2e%2e%2f\u003c/code\u003e, etc.) in query parameters, particularly those associated with static file handlers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T22:25:27Z","date_published":"2026-07-23T22:25:27Z","id":"https://feed.craftedsignal.io/briefs/2026-07-microweber-path-traversal/","summary":"An unauthenticated path traversal vulnerability (CVE-2026-65694) in the static file controller of Microweber CMS, affecting versions through 2.0.20, allows remote attackers to read arbitrary files by supplying directory traversal sequences in the 'path' query parameter via a single unauthenticated HTTP GET request, potentially disclosing sensitive information like environment configuration files containing credentials or system files.","title":"Microweber CMS Path Traversal Vulnerability (CVE-2026-65694)","url":"https://feed.craftedsignal.io/briefs/2026-07-microweber-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Microweber CMS","version":"https://jsonfeed.org/version/1.1"}