
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5331 is a path traversal vulnerability affecting OpenCart version 4.1.0.3, specifically in the installer.php file of the Extension Installer Page component. The vulnerability allows a remote attacker with high-level privileges to manipulate file path inputs, potentially accessing files and directories outside the intended restricted scope. It was published on April 2, 2026, with the exploit publicly disclosed at the time of disclosure. The vendor was contacted prior to disclosure but did not respond. The CVSS v3.1 base score is 4.7 (Medium), and the CVSS v4.0 base score is 5.1 (Medium) (GitHub Advisory, VulDB).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'), where the application fails to properly neutralize special path elements (e.g., ../) in user-supplied input passed to installer.php on the Extension Installer Page (GitHub Advisory). An attacker must be authenticated with high privileges (e.g., an administrator account) to reach the vulnerable component, and the attack requires no user interaction. The exploit has been publicly disclosed via a Google Drive document referenced in the VulDB submission, though specific payload details are not fully documented in public sources (VulDB).
Successful exploitation could allow a high-privileged attacker to read, and potentially modify, files outside the web application's intended directory structure, resulting in low-level impacts to confidentiality, integrity, and availability. This could expose sensitive server-side configuration files, credentials, or application data, and may enable limited file manipulation. Because the exploit is publicly disclosed, the risk of opportunistic exploitation by authenticated attackers (e.g., compromised admin accounts) is elevated (GitHub Advisory, VulDB).
A proof-of-concept exploit has been publicly disclosed via a Google Drive link referenced in the VulDB submission, though no evidence of active in-the-wild exploitation has been reported as of the time of this report (GitHub Advisory). The EPSS score is approximately 0.079%–0.161% (37th percentile), indicating a relatively low but non-negligible probability of exploitation within 30 days. No threat actor attribution has been identified, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
installer.php.../../) in the relevant input field or file upload parameter handled by installer.php.installer.php with URL-encoded or raw path traversal sequences (e.g., ../, %2e%2e%2f, ..%2f) in parameters or file upload fields./etc/passwd, server configuration files, or parent directory files).No official patch has been released by the OpenCart vendor as of the time of this report, and the vendor did not respond to the researcher's disclosure (GitHub Advisory). Recommended interim mitigations include: restricting administrative panel access to trusted IP addresses via firewall or web server configuration; applying the principle of least privilege to admin accounts; monitoring file system and web server access logs for path traversal patterns; and hardening file permissions on the OpenCart installation directory to prevent unauthorized file access. Organizations should monitor for an official patch from OpenCart and apply it promptly upon release (VulDB).
The vulnerability was assigned and published by VulDB and subsequently indexed by NVD, ENISA EUVD, and Red Hat CVE databases. No notable public commentary from prominent security researchers or significant media coverage has been identified beyond standard vulnerability database aggregation. The vendor's lack of response to the coordinated disclosure was noted in the advisory (GitHub Advisory, VulDB).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."