CVE-2026-56845: An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request
An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-56845
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-56845 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for An unauthenticated path
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-69095: OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path t…nvd · 2026-08-03
- unknownCVE-2026-18140 - Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated re…aws · 2026-07-31
- mediumCVE-2026-16531: An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmpro…nvd · 2026-07-30
- highCVE-2026-67185: TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated atta…nvd · 2026-07-28
- unknownCVE-2026-59251: Allocation of resources without limits in Erlang/OTP public_key certificate path validation al…nvd · 2026-07-27
- highCVE-2026-66050: NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file trans…nvd · 2026-07-27
More from NVD Recent CVEs
- mediumCVE-2026-8508: An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S…2026-08-04
- highCVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel …2026-08-04
- mediumCVE-2026-18720: A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown co…2026-08-04
- mediumCVE-2026-17614: A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileReposito…2026-08-04
- mediumCVE-2026-18719: A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the fil…2026-08-04