Description
OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.php. An authenticated administrator can submit a non-HTML upload filename matching an existing file in the application's working directory. The application passes the user-controlled filename to unlink() when rejecting the upload, potentially causing file deletion and denial of service.
Published: 2026-09-15
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated arbitrary file deletion causing denial of service
Action: Patch now
AI Analysis

Impact

OneNav v1.2.4 contains a flaw where an authenticated administrator can trigger deletion of arbitrary files in the application’s working directory by uploading a non‑HTML file whose name matches an existing file. The upload handler passes the attacker‑controlled filename directly to the unlink() function when rejecting the upload, resulting in the targeted file being deleted. This loss can lead to denial of service by removing critical configuration or data files and may erase sensitive information stored within the application directory. The weakness involves improper authorization (CWE‑706).

Affected Systems

The affected product is the OneNav web application, version 1.2.4. No other vendor information or package names beyond the GitHub repository are provided. The vulnerability is present in the Api::upload() method in Api.php.

Risk and Exploitability

The flaw requires authenticated administrator privileges; no external conditions are mentioned. The EPSS score of <1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. However, within installations where administrative accounts are exposed or weakly protected, an attacker could delete configuration or data files, leading to downtime and potential loss of critical information. The attack path is straightforward: authenticate, submit a POST to the upload API with a non‑HTML file whose name matches an existing file; the server deletes that file when rejecting the upload. The weakness does not allow arbitrary code execution.

Generated by OpenCVE AI on September 22, 2026 at 21:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update OneNav to a version that removes the unlink call on rejected uploads.
  • If an immediate update is not possible, restrict administrative privileges to only those necessary for upload management and monitor upload activities for suspicious file names.
  • As a temporary safeguard, disable the API endpoint responsible for file uploads until the patch is applied, preventing the deletion path from being exercised.

Generated by OpenCVE AI on September 22, 2026 at 21:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator-Only File Deletion in OneNav 1.2.4 via Unchecked Upload Filename
Weaknesses CWE-20

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-706
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Sun, 20 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Authenticated Administrator-Only File Deletion in OneNav 1.2.4 via Unchecked Upload Filename
Weaknesses CWE-20

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Authenticated Arbitrary File Deletion in OneNav 1.2.4
Weaknesses CWE-20
CWE-22

Wed, 16 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Authenticated Arbitrary File Deletion in OneNav 1.2.4
Weaknesses CWE-20
CWE-22

Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.php. An authenticated administrator can submit a non-HTML upload filename matching an existing file in the application's working directory. The application passes the user-controlled filename to unlink() when rejecting the upload, potentially causing file deletion and denial of service.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T15:00:43.194Z

Reserved: 2026-09-10T00:00:00.000Z

Link: CVE-2026-88621

cve-icon Vulnrichment

Updated: 2026-09-22T15:00:35.819Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:39.157

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-88621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:45:06Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference