PatchSiren cyber security CVE debrief
CVE-2026-35174 xenocrat CVE debrief
CVE-2026-35174 is a path traversal vulnerability in Chyrp Lite, a ultra-lightweight blogging engine. An administrator or a user with Change Settings permission can change the uploads path to any folder, allowing them to download any file on the server, including config.json.php with database credentials, and overwrite critical system files, leading to remote code execution. The vulnerability is fixed in version 2026.01. Affected users should update immediately and review system logs for potential exploitation.
- Vendor
- xenocrat
- Product
- chyrp-lite
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
Users of Chyrp Lite, especially those with administrative or Change Settings permissions, should be aware of this vulnerability and take immediate action to update to version 2026.01 or apply mitigations. System administrators and security teams should review system logs for potential exploitation and implement additional security measures to prevent further exploitation.
Technical summary
A path traversal vulnerability exists in the administration console of Chyrp Lite, allowing an administrator or a user with Change Settings permission to change the uploads path to any folder. This can lead to downloading any file on the server, including config.json.php with database credentials, and overwriting critical system files, resulting in remote code execution. The vulnerability has a CVSS score of 9.1 and is classified as CRITICAL. Defenders should prioritize updating to version 2026.01 and monitor system logs for suspicious activity.
Defensive priority
High
Recommended defensive actions
- Update Chyrp Lite to version 2026.01 or later
- Restrict Change Settings permissions to trusted users
- Monitor server logs for suspicious activity
- Implement additional security measures, such as file access controls and monitoring
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-04-06T18:16:43.677Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS score of 9.1 and is classified as CRITICAL. Evidence of exploitation is not currently available, but defenders should verify system logs for suspicious activity related to file access and system modifications.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-35174 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-35174
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-35174 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35174
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/xenocrat/chyrp-lite/security/advisories/GHSA-p6pf-2grm-8257
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.