Vulnerability Description
CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-48820?
CVE-2026-48820 is a documented vulnerability. CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() d...
How severe is CVE-2026-48820?
CVSS scoring is not yet available for CVE-2026-48820. Check NVD for updates.
Is there a patch for CVE-2026-48820?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.