CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64967

unknowncovered by 1 sourcefirst seen 2026-08-20
A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access arbitrary files outside the intended logs directory. This can lead to unauthorized access to sensitive files and other resources accessible to the web server process. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

⚡ Watch CVE-2026-64967

Get an email if CVE-2026-64967 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-64967

CVE.org record

Embed the live status

CVE-2026-64967 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64967 status](https://www.csirts.com/badge/CVE-2026-64967)](https://www.csirts.com/cve/CVE-2026-64967)