CVE-2026-6568 is a path traversal vulnerability affecting KodCloud's KodExplorer file manager up to version 4.52, specifically within the Public Share Handler component's initShareOld function in share.class.php. The flaw allows remote attackers to manipulate the path argument to traverse the file system and access unauthorized files or directories. The vulnerability carries a CVSS score of 7.3 (HIGH) with a network-based attack vector requiring no authentication, low complexity, and no user interaction. The impact is moderate, potentially compromising confidentiality, integrity, and availability of affected systems. The FAUCET Risk Score of 47.0 indicates elevated concern, though the EPSS score of 0.0009 suggests currently low exploitation likelihood compared to other vulnerabilities. Exploitation status indicates active interest despite low current exploitation rates. The vulnerability has been publicly disclosed with exploit code available, placing organizations running affected KodExplorer versions at risk. The vendor's lack of response to early disclosure notification compounds the risk, as no official patches are currently available to remediate the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Kodcloud | KodExplorer | 4.0, 4.1, 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.16, 4.17, 4.18, 4.19, 4.2, 4.20, 4.21, 4.22, 4.23, 4.24, 4.25, 4.26, 4.27, 4.28, 4.29, 4.3, 4.30, 4.31, 4.32, 4.33, 4.34, 4.35, 4.36, 4.37, 4.38, 4.39, 4.4, 4.40, 4.41, 4.42, 4.43, 4.44, 4.45, 4.46, 4.47, 4.48, 4.49, 4.5, 4.50, 4.51, 4.52, 4.6, 4.7, 4.8, 4.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.