CVE-2026-5014 is a path traversal vulnerability found in elecV2 elecV2P versions up to 3.8.3, specifically within the `path.join` function of the `/log/` component's Wildcard Handler. This vulnerability has a CVSS v3.1 score of 5.3 (Medium), indicating it can be exploited remotely with low attack complexity and no user interaction, potentially leading to unauthorized information disclosure. Although the exploit has been made public, there is currently no evidence of active exploitation, and no public exploit modules are available in common frameworks like Metasploit or ExploitDB. The project maintainers were informed of the issue but have not yet responded, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ElecV2 | ElecV2P | 3.8.0, 3.8.1, 3.8.2, 3.8.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.