Description
Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP process. Article image metadata is used to construct a filesystem path and is passed to `unlink()` without path traversal or directory validation.
Published: 2026-10-05
Score: n/a
EPSS: n/a
KEV: No
Impact: Arbitrary File Deletion via Directory Traversal
Action: Assess Impact
AI Analysis

Impact

This vulnerability enables an authenticated user in the Feehi CMS backend who has permission to edit articles to delete any file that is writable by the PHP process. Article image metadata, which may contain user-controlled values, is used directly to build a filesystem path that is passed to unlink() without any validation or sanitization, allowing deletion of arbitrary files beyond the intended image directory. The flaw constitutes a classic directory traversal which can compromise the integrity and confidentiality of the server’s file system.

Affected Systems

The flaw is present in Feehi CMS version 2.1.1. Administrators of websites using this CMS should verify whether they are running this specific release and whether article deletion or editing features are enabled for accounts with write access.

Risk and Exploitability

The vulnerability requires an authenticated backend user, so an attacker must first obtain legitimate user credentials or privilege escalation. Once the edit permission is granted, the attacker can supply crafted image metadata to delete critical files, potentially leading to denial of service or destruction of data. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog. The absence of an exploit probability metric means the risk is uncertain, but the severity of arbitrary file removal warrants prompt action.

Generated by OpenCVE AI on October 5, 2026 at 21:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the vendor’s website or repository for an updated release that addresses the directory traversal flaw; apply it at the earliest convenience.
  • If an update is not yet available, restrict the article edit permission solely to trusted administrators and review account privileges to limit the number of users able to modify content.
  • Audit the filesystem permissions of the PHP process to ensure that it can write only to the designated image directory and not to system or configuration files; remove unnecessary write access where possible.

Generated by OpenCVE AI on October 5, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Title Directory Traversal Allows Arbitrary File Deletion in Feehi CMS
Weaknesses CWE-22
CWE-36

Mon, 05 Oct 2026 20:15:00 +0000

Type Values Removed Values Added
Description Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP process. Article image metadata is used to construct a filesystem path and is passed to `unlink()` without path traversal or directory validation.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-05T20:06:04.480Z

Reserved: 2026-09-22T00:00:00.000Z

Link: CVE-2026-95264

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T20:17:29.187

Modified: 2026-10-05T20:17:29.187

Link: CVE-2026-95264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:45:20Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-36

    Absolute Path Traversal