PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35174 xenocrat CVE debrief

CVE-2026-35174 is a path traversal vulnerability in Chyrp Lite, a ultra-lightweight blogging engine. An administrator or a user with Change Settings permission can change the uploads path to any folder, allowing them to download any file on the server, including config.json.php with database credentials, and overwrite critical system files, leading to remote code execution. The vulnerability is fixed in version 2026.01. Affected users should update immediately and review system logs for potential exploitation.

Vendor
xenocrat
Product
chyrp-lite
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-07-24
Advisory published
2026-04-06
Advisory updated
2026-07-24

Who should care

Users of Chyrp Lite, especially those with administrative or Change Settings permissions, should be aware of this vulnerability and take immediate action to update to version 2026.01 or apply mitigations. System administrators and security teams should review system logs for potential exploitation and implement additional security measures to prevent further exploitation.

Technical summary

A path traversal vulnerability exists in the administration console of Chyrp Lite, allowing an administrator or a user with Change Settings permission to change the uploads path to any folder. This can lead to downloading any file on the server, including config.json.php with database credentials, and overwriting critical system files, resulting in remote code execution. The vulnerability has a CVSS score of 9.1 and is classified as CRITICAL. Defenders should prioritize updating to version 2026.01 and monitor system logs for suspicious activity.

Defensive priority

High

Recommended defensive actions

  • Update Chyrp Lite to version 2026.01 or later
  • Restrict Change Settings permissions to trusted users
  • Monitor server logs for suspicious activity
  • Implement additional security measures, such as file access controls and monitoring
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-04-06T18:16:43.677Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS score of 9.1 and is classified as CRITICAL. Evidence of exploitation is not currently available, but defenders should verify system logs for suspicious activity related to file access and system modifications.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T18:16:43.677Z and has not been modified since then. The NVD entry is currently Analyzed.