CVE-2022-26960
PHP vulnerability analysis and mitigation

Overview

elFinder through version 2.1.60 is affected by a path traversal vulnerability (CVE-2022-26960) that was discovered in March 2022. This vulnerability allows unauthenticated remote attackers to read, write, and browse files outside the configured document root directory. The issue stems from improper handling of absolute file paths in the connector.minimal.php component (NVD, Synacktiv).

Technical details

The vulnerability exists in the getFullPath function within elFinderVolumeDriver.class.php, which fails to properly sanitize path traversal sequences. The function uses an incorrect regex pattern (#(/)/+/../#) for normalizing paths, which allows attackers to bypass directory traversal protections by using double slash sequences (//) followed by ../ patterns. The vulnerability received a CVSS v3.1 score of 9.1 CRITICAL (NVD, Synacktiv).

Impact

The vulnerability allows attackers to read, write, and browse files outside the configured document root directory. With appropriate permissions, attackers can perform various actions including searching, uploading files, and browsing parent directories. In some cases, this can lead to remote code execution by modifying critical files such as authorized_keys or crontabs (Synacktiv).

Exploitability

The vulnerability can be exploited by unauthenticated remote attackers. For versions prior to 2.1.59, exploitation is straightforward. For version 2.1.60, exploitation requires knowledge of the file system path to the elFinder root directory, which can potentially be guessed, brute-forced, or leaked through other vulnerabilities (Synacktiv).

Mitigation and workarounds

The vulnerability was patched in elFinder version 2.1.61. Organizations should upgrade to this version or later to address the issue. The fix includes improved path validation in the _joinPath function and additional security measures for handling file paths (Synacktiv).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-46670CRITICAL9.8
  • PHP logoPHP
  • yeswiki/yeswiki
NoYesAug 11, 2026
GHSA-wg23-69c2-gjc8CRITICAL9.1
  • PHP logoPHP
  • craftcms/cms
NoYesAug 07, 2026
CVE-2026-71488HIGH7.5
  • PHP logoPHP
  • commonmark
NoYesAug 06, 2026
CVE-2026-62996MEDIUM6.9
  • PHP logoPHP
  • smarty/smarty
NoYesAug 07, 2026
CVE-2026-62992MEDIUM6.9
  • PHP logoPHP
  • smarty/smarty
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management