Vulnerability Description
Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET /public/get-file/{path} endpoint. The path route parameter is passed directly to file_get_contents() without canonicalization against a permitted base directory, enabling attackers to retrieve sensitive files accessible to the PHP-FPM worker process without using directory traversal sequences.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/Volmarg/personal-management-system/commit/a0443570e105ed4835c
- https://github.com/Volmarg/personal-management-system/commit/fb9d3679d5b28977ef5
- https://www.vulncheck.com/advisories/volmarg-personal-management-system-path-tra
FAQ
What is CVE-2026-40526?
CVE-2026-40526 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET /public/get-fil...
How severe is CVE-2026-40526?
CVE-2026-40526 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-40526?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.