Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 10 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succeeds, allowing authenticated attackers to submit traversal sequences or absolute paths in the file parameter to read, write, or delete files outside the configured document root. | |
| Title | ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement | |
| First Time appeared |
Icecoder
Icecoder icecoder |
|
| Weaknesses | CWE-22 CWE-697 |
|
| CPEs | cpe:2.3:a:icecoder:icecoder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Icecoder
Icecoder icecoder |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-10T14:05:49.993Z
Reserved: 2026-07-20T18:27:48.161Z
Link: CVE-2026-64836
Updated: 2026-09-10T14:05:44.511Z
Status : Received
Published: 2026-09-10T14:17:03.317
Modified: 2026-09-10T15:17:35.947
Link: CVE-2026-64836
No data.
OpenCVE Enrichment
No data.
