high · CVSS v3 7.1 · CVSS v4 7.1
CVE-2026-104478
Formwork versions prior to 2.3.13 have a path traversal flaw in BackupController that lets authenticated panel users read or delete arbitrar
Overview
Formwork versions prior to 2.3.13 have a path traversal flaw in BackupController that lets authenticated panel users read or delete arbitrary files. The vulnerability is triggered by a base64-encoded backslash-separated payload that bypasses PHP basename on Linux. It allows attackers with backup download or delete permissions to access files outside the backup directory.
Description
Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.
Impact
Confidentiality: attackers can read sensitive files. Integrity: attackers can delete or modify files, potentially corrupting backups. Availability: removal of critical files may disrupt backup operations. The flaw affects authenticated panel users who have backup download or delete permissions.
Remediation
Apply the official patch to upgrade to Formwork 2.3.13 or later. If an upgrade is not immediately possible, disable the backup feature or remove backup download/delete permissions from all users. Additionally, validate and sanitize file paths on the server side, enforce a whitelist of allowed directories, and avoid using base64 decoding for path components.
Risk context
The vulnerability is rated high with a CVSS v3 score of 7.1. No EPSS data is available, but the flaw can be exploited by any authenticated user with backup permissions, making it a serious risk for organizations running affected Formwork versions.
Affected products
- Formwork 2.3.12
- Formwork 2.3.11
- Formwork 2.3.10
- Formwork 2.3.9
- Formwork 2.3.8
- Formwork 2.3.7
- Formwork 2.3.6
- Formwork 2.3.5
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 7.1
- CVSS v4
- 7.1
- EPSS
- —