PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35174 xenocrat CVE debrief

CVE-2026-35174 is a path traversal vulnerability in Chyrp Lite, a ultra-lightweight blogging engine. An administrator or a user with Change Settings permission can change the uploads path to any folder, allowing them to download any file on the server, including config.json.php with database credentials, and overwrite critical system files, leading to remote code execution. The vulnerability is fixed in version 2026.01. Affected users should update immediately and review system logs for potential exploitation.

Vendor
xenocrat
Product
chyrp-lite
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-07-24
Advisory published
2026-04-06
Advisory updated
2026-07-24

Who should care

Users of Chyrp Lite, especially those with administrative or Change Settings permissions, should be aware of this vulnerability and take immediate action to update to version 2026.01 or apply mitigations. System administrators and security teams should review system logs for potential exploitation and implement additional security measures to prevent further exploitation.

Technical summary

A path traversal vulnerability exists in the administration console of Chyrp Lite, allowing an administrator or a user with Change Settings permission to change the uploads path to any folder. This can lead to downloading any file on the server, including config.json.php with database credentials, and overwriting critical system files, resulting in remote code execution. The vulnerability has a CVSS score of 9.1 and is classified as CRITICAL. Defenders should prioritize updating to version 2026.01 and monitor system logs for suspicious activity.

Defensive priority

High

Recommended defensive actions

  • Update Chyrp Lite to version 2026.01 or later
  • Restrict Change Settings permissions to trusted users
  • Monitor server logs for suspicious activity
  • Implement additional security measures, such as file access controls and monitoring
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-04-06T18:16:43.677Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS score of 9.1 and is classified as CRITICAL. Evidence of exploitation is not currently available, but defenders should verify system logs for suspicious activity related to file access and system modifications.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-35174 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-35174

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-35174 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35174

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.