CVE-2026-67246: A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated befo
A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated before being used for file access. An authenticated attacker can exploit this issue to access or manipulate files outside the intended wallpaper directory, subject to user permissions and filesystem restrictions.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-67246
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-672460.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-67246 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for A path traversal
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-67309: Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kuberne…nvd · 2026-08-01
- mediumCVE-2026-15601: The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulner…nvd · 2026-08-01
- highCVE-2026-15450: The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary f…nvd · 2026-08-01
- unknownCVE-2026-15244: The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against direc…nvd · 2026-08-01
- highGHSA-6hm5-jgcp-p838: Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary Fi…ghsa · 2026-07-31
- highGHSA-xh95-f55m-82fw: Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that a…ghsa · 2026-07-31
More from NVD Recent CVEs
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01
- mediumCVE-2026-67354: guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in Re…2026-08-01
- mediumCVE-2026-67353: guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the Cook…2026-08-01
- highCVE-2026-67352: luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_…2026-08-01
- mediumCVE-2026-67344: ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYP…2026-08-01