CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73849

criticalCVSS 9.8covered by 1 sourcefirst seen 2026-08-14
Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote attacker can submit hostname, dbuser, dbpasswd, dbname, dbprefix, username, password, and email values to cause file_put_contents('config.php', $config) to overwrite the configuration with attacker-controlled database settings and create a new administrator account. No fixed version is available as of this review.

⚡ Watch CVE-2026-73849

Get an email if CVE-2026-73849 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-73849

CVE.org record

Embed the live status

CVE-2026-73849 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73849 status](https://www.csirts.com/badge/CVE-2026-73849)](https://www.csirts.com/cve/CVE-2026-73849)