Published:2026/09/11  Last Updated:2026/09/11

JVN#20829034
a-blog cms vulnerable to path traversal

Overview

a-blog cms provided by appleple inc. contains a path traversal vulnerability.

Products Affected

  • a-blog cms versions 3.2.33 and earlier

Description

a-blog cms provided by appleple inc. contains the following vulnerability.

  • Path traversal (CWE-22)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 6.9
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Base Score 6.5
    • CVE-2026-87727
You are affected by this vulnerability only when "Attaching files to emails addressed to the administrator" is enabled in the form settings.

Impact

Arbitrary files on the system may be read or deleted by a remote unauthenticated attacker.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

According to the developer, no update will be provided for versions 2.11 or earlier, as support for those versions has already ended. Therefore, users of those versions are recommended to upgrade to version 3.0 or later.

Apply the Workaround
The developer recommends applying the workaround until the product is updated.

For more details, refer to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
appleple inc. Vulnerable 2026/09/11 appleple inc. website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

hibiki moriyama of STNet, Incorporated reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-87727
JVN iPedia JVNDB-2026-000132