PatchSiren cyber security CVE debrief
CVE-2026-73849 emlog CVE debrief
CVE-2026-73849 is a critical vulnerability in Emlog, an open-source website building system. The vulnerability exists in versions 2.6.26 and earlier, where the install.php file accepts an action=reinstall parameter without authentication, allowing a remote attacker to overwrite configuration files with attacker-controlled database settings and create a new administrator account.
- Vendor
- emlog
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-14
- Original CVE updated
- 2026-09-16
- Advisory published
- 2026-08-14
- Advisory updated
- 2026-09-16
Who should care
Defenders responsible for Emlog installations, especially version 2.6.26 and earlier, should verify their installations and consider upgrading to a fixed version if available. They should also monitor for suspicious activity on Emlog installations and review compensating controls for exposed systems while remediation is scheduled and verified.
Why it matters
CVE-2026-73849 is a critical vulnerability in Emlog that allows remote attackers to create new administrator accounts and overwrite configuration files. Defenders responsible for Emlog installations should verify their installations and consider upgrading to a fixed version if available.
- Remote attackers can create new administrator accounts
- Configuration files can be overwritten with attacker-controlled database settings
- Defenders need to verify Emlog installations and consider upgrading to a fixed version
Technical summary
The install.php file in Emlog versions 2.6.26 and earlier accepts an action=reinstall parameter without authentication, allowing a remote attacker to overwrite configuration files with attacker-controlled database settings and create a new administrator account. This vulnerability exists in the install.php file, which deliberately skips the already-installed check when the action=reinstall parameter is provided. Defenders should prioritize verifying Emlog installations, especially version 2.6.26 and earlier, and consider upgrading to a fixed version if available.
Defensive priority
Defenders should prioritize verifying Emlog installations, especially version 2.6.26 and earlier, and consider upgrading to a fixed version if available.
Recommended defensive actions
- Verify Emlog installations, especially version 2.6.26 and earlier
- Consider upgrading to a fixed version if available
- Monitor for suspicious activity on Emlog installations
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the vulnerability. A fixed version is not available as of this review. Defenders should verify Emlog installations, especially version 2.6.26 and earlier, and consider upgrading to a fixed version if available. The vulnerability allows remote attackers to create new administrator accounts and overwrite configuration files with attacker-controlled database settings. Evidence is limited to CVE and NVD details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73849 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73849
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73849 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73849
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/emlog/emlog/security/advisories/GHSA-v5qq-p8mp-3gxm
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.