PatchSiren cyber security CVE debrief
CVE-2026-35174 xenocrat CVE debrief
CVE-2026-35174 is a path traversal vulnerability in Chyrp Lite, a ultra-lightweight blogging engine. An administrator or a user with Change Settings permission can change the uploads path to any folder, allowing them to download any file on the server, including config.json.php with database credentials, and overwrite critical system files, leading to remote code execution. The vulnerability is fixed in version 2026.01. Affected users should update immediately and review system logs for potential exploitation.
- Vendor
- xenocrat
- Product
- chyrp-lite
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
Users of Chyrp Lite, especially those with administrative or Change Settings permissions, should be aware of this vulnerability and take immediate action to update to version 2026.01 or apply mitigations. System administrators and security teams should review system logs for potential exploitation and implement additional security measures to prevent further exploitation.
Technical summary
A path traversal vulnerability exists in the administration console of Chyrp Lite, allowing an administrator or a user with Change Settings permission to change the uploads path to any folder. This can lead to downloading any file on the server, including config.json.php with database credentials, and overwriting critical system files, resulting in remote code execution. The vulnerability has a CVSS score of 9.1 and is classified as CRITICAL. Defenders should prioritize updating to version 2026.01 and monitor system logs for suspicious activity.
Defensive priority
High
Recommended defensive actions
- Update Chyrp Lite to version 2026.01 or later
- Restrict Change Settings permissions to trusted users
- Monitor server logs for suspicious activity
- Implement additional security measures, such as file access controls and monitoring
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-04-06T18:16:43.677Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS score of 9.1 and is classified as CRITICAL. Evidence of exploitation is not currently available, but defenders should verify system logs for suspicious activity related to file access and system modifications.
Official resources
-
CVE-2026-35174 CVE record
CVE.org
-
CVE-2026-35174 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T18:16:43.677Z and has not been modified since then. The NVD entry is currently Analyzed.