CVE-2026-33686: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33686 is a path traversal vulnerability (CWE-22) in the FileUtil class of the code16/sharp PHP CMS package, allowing authenticated attackers to write files outside the intended temporary directory. It affects all versions of code16/sharp prior to 9.20.0 and was disclosed on March 23, 2026, with the patch merged on March 20, 2026. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Sharp Security Advisory).

Technical details

The root cause lies in src/Utils/FileUtil.php, where the FileUtil::explodeExtension() function extracts a file's extension by splitting the filename at the last dot using strrpos(). The extracted extension is never sanitized — while a normalizeName() function cleans the base filename, it does not process the extension, meaning path separators (e.g., /) injected into the extension survive and are passed directly into the storeAs() storage function. This allows an attacker to craft a filename with a malicious extension containing path traversal sequences, causing files to be written to arbitrary locations on the filesystem. The vulnerability was confirmed in a local proof-of-concept that chained it with CWE-434 (Unrestricted File Upload) to achieve full traversal (GitHub Advisory, Sharp Security Advisory).

Impact

Successful exploitation allows an authenticated attacker with low privileges to write arbitrary files outside the intended tmp directory, potentially overwriting critical application files such as .env or other configuration files. This can lead to full compromise of confidentiality (exposure of secrets/credentials), integrity (modification of application behavior), and availability (disruption of service). When chained with an unrestricted file upload vulnerability (CWE-434), the impact is rated High across all three CIA dimensions (GitHub Advisory).

Exploitability

There is no evidence of public exploit code or in-the-wild exploitation at this time, though a local proof-of-concept was developed by the reporter (zaurgsynv) to confirm the traversal when chained with CWE-434 (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.031% (0.00063), placing it in the 9th percentile for exploitation likelihood (GitHub Advisory, Feedly).

Exploitation steps

  1. Authenticate: Obtain valid low-privilege credentials to the Sharp CMS application (any authenticated user role is sufficient).
  2. Identify file upload functionality: Locate a Sharp CMS feature that accepts file uploads and passes filenames through the FileUtil::explodeExtension() function in src/Utils/FileUtil.php.
  3. Craft malicious filename: Prepare a file with a filename containing path traversal sequences embedded in the extension, e.g., malicious.../../config/.env or shell../../../public/shell.php, so that the extension portion contains / path separators.
  4. Upload the file: Submit the crafted file via the application's upload endpoint. The normalizeName() function sanitizes only the base name, leaving the traversal sequences in the extension intact.
  5. Trigger storage: The unsanitized extension is passed to storeAs(), causing the file to be written outside the intended tmp directory to the attacker-controlled path.
  6. Achieve objective: Overwrite critical files (e.g., .env to expose or modify credentials/configuration) or, when chained with CWE-434, write a web shell to a publicly accessible directory for remote code execution (GitHub Advisory, Sharp Security Advisory).

Indicators of compromise

  • File System: Unexpected files appearing outside the application's tmp or storage directories; modifications to .env, config/*.php, or other configuration files with unusual timestamps; new PHP files (potential web shells) in publicly accessible directories (e.g., public/).
  • Logs: Web server access logs showing file upload requests with filenames containing ../, %2F, or other path separator encodings in the extension field; application logs recording storeAs() calls with paths resolving outside the intended storage directory.
  • Network: Repeated authenticated POST requests to Sharp CMS upload endpoints with anomalous Content-Disposition filename values containing path traversal sequences.
  • Process: Unexpected PHP process execution originating from newly created files in web-accessible directories, potentially indicating a chained web shell upload.

Mitigation and workarounds

Upgrade code16/sharp to version 9.20.0 or later, which fixes the issue by replacing strrpos() with pathinfo(PATHINFO_EXTENSION) for extension extraction and applying strict regex sanitization to both the base name and extension before passing to storeAs() (Sharp PR #715, GitHub Advisory). As interim mitigations: restrict file upload functionality to the minimum required user roles, enforce strict file system permissions to prevent the web server process from writing outside designated directories, and monitor file system activity for unexpected modifications to critical configuration files.

Community reactions

The vulnerability was reported by security researcher zaurgsynv and covered by The Hacker Wire, which published a technical write-up titled "Sharp CMS – Path Traversal in FileUtil (CVE-2026-33686)" (The Hacker Wire). The disclosure was also noted on Mastodon by The Hacker Wire's account and tracked by several CVE aggregation platforms. No major vendor statements or widespread community controversy have been observed beyond standard advisory publication.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management