Vulnerability Description
OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extracted paths stay inside the intended extraction directory. An attacker can craft a malicious extension containing file path traversal sequences, such as ../. With this vulnerability, an attacker can write files, such as a PHP web shell, into the webroot directory.
CVSS Score
CRITICAL
References
FAQ
What is CVE-2026-18412?
CVE-2026-18412 is a vulnerability with a CVSS score of 9.1 (CRITICAL). OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extracte...
How severe is CVE-2026-18412?
CVE-2026-18412 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-18412?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.