CVE-2026-55231: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in givanz Vvveb
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel user who holds backup access (default role site_admin or higher) read and delete arbitrary files on a server. An attacker can recover database credentials from config/db.php, read host files such as /etc/passwd, and delete config/db.php to push a site back into install mode for a full takeover. This issue has been patched in version 1.0.8.6.
AI Analysis
Technical Summary
CVE-2026-55231 is a path traversal vulnerability (CWE-22) in the Vvveb CMS before version 1.0.8.6. The issue arises from an improper limitation of pathname sanitization in the backup functionality accessible to authenticated admin users with the site_admin role or higher. Exploiting this flaw, an attacker can read arbitrary files including config/db.php and /etc/passwd, and delete files such as config/db.php to trigger a site reinstall, potentially leading to full site takeover. The vulnerability is patched in version 1.0.8.6.
Potential Impact
An attacker with authenticated admin-panel access and backup privileges can read sensitive files including database credentials and system files, and delete configuration files to cause a site reinstall. This can lead to full site compromise and loss of data integrity and availability.
Mitigation Recommendations
Upgrade Vvveb CMS to version 1.0.8.6 or later where this vulnerability is patched. No other mitigation is required as the fix addresses the root cause.
CVE-2026-55231: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in givanz Vvveb
Description
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel user who holds backup access (default role site_admin or higher) read and delete arbitrary files on a server. An attacker can recover database credentials from config/db.php, read host files such as /etc/passwd, and delete config/db.php to push a site back into install mode for a full takeover. This issue has been patched in version 1.0.8.6.
CVSS v3.1
Score 7.2high
Affected software
givanz
Vvveb
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-55231 is a path traversal vulnerability (CWE-22) in the Vvveb CMS before version 1.0.8.6. The issue arises from an improper limitation of pathname sanitization in the backup functionality accessible to authenticated admin users with the site_admin role or higher. Exploiting this flaw, an attacker can read arbitrary files including config/db.php and /etc/passwd, and delete files such as config/db.php to trigger a site reinstall, potentially leading to full site takeover. The vulnerability is patched in version 1.0.8.6.
Potential Impact
An attacker with authenticated admin-panel access and backup privileges can read sensitive files including database credentials and system files, and delete configuration files to cause a site reinstall. This can lead to full site compromise and loss of data integrity and availability.
Mitigation Recommendations
Upgrade Vvveb CMS to version 1.0.8.6 or later where this vulnerability is patched. No other mitigation is required as the fix addresses the root cause.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-16T16:44:00.623Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abeae1ca43b0b3b89e80a2a
Added to database: 10/01/2026, 19:01:48 UTC
Last enriched: 10/01/2026, 19:16:06 UTC
Last updated: 10/02/2026, 03:08:56 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.