JVN#20829034
a-blog cms vulnerable to path traversal
Overview
a-blog cms provided by appleple inc. contains a path traversal vulnerability.
Products Affected
- a-blog cms versions 3.2.33 and earlier
Description
a-blog cms provided by appleple inc. contains the following vulnerability.
- Path traversal (CWE-22)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 6.9
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Base Score 6.5
- CVE-2026-87727
Impact
Arbitrary files on the system may be read or deleted by a remote unauthenticated attacker.
Solution
Update the Software
Update the software to the latest version according to the information provided by the developer.
According to the developer, no update will be provided for versions 2.11 or earlier, as support for those versions has already ended. Therefore, users of those versions are recommended to upgrade to version 3.0 or later.
Apply the Workaround
The developer recommends applying the workaround until the product is updated.
For more details, refer to the information provided by the developer.
Vendor Status
| Vendor | Status | Last Update | Vendor Notes |
|---|---|---|---|
| appleple inc. | Vulnerable | 2026/09/11 | appleple inc. website |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
hibiki moriyama of STNet, Incorporated reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-87727 |
| JVN iPedia |
JVNDB-2026-000132 |