CVE-2026-32567 is a Path Traversal vulnerability (CWE-22) affecting the icopydoc YML for Yandex Market plugin, specifically versions prior to 5.3.0. This flaw allows an attacker to access files and directories outside of the intended restricted directory. Rated as Medium severity (CVSS 6.8), it has a network attack vector and low attack complexity, but requires high privileges for exploitation. Successful exploitation could lead to high confidentiality impact, allowing unauthorized disclosure of sensitive information. There is currently no evidence of active exploitation, no public exploit code available, and no community discussion identified for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Icopydoc | YML For Yandex Market | >= n/a, <= < 5.3.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.