CVE-2026-5331
OpenCart vulnerability analysis and mitigation

Overview

CVE-2026-5331 is a path traversal vulnerability affecting OpenCart version 4.1.0.3, specifically in the installer.php file of the Extension Installer Page component. The vulnerability allows a remote attacker with high-level privileges to manipulate file path inputs, potentially accessing files and directories outside the intended restricted scope. It was published on April 2, 2026, with the exploit publicly disclosed at the time of disclosure. The vendor was contacted prior to disclosure but did not respond. The CVSS v3.1 base score is 4.7 (Medium), and the CVSS v4.0 base score is 5.1 (Medium) (GitHub Advisory, VulDB).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'), where the application fails to properly neutralize special path elements (e.g., ../) in user-supplied input passed to installer.php on the Extension Installer Page (GitHub Advisory). An attacker must be authenticated with high privileges (e.g., an administrator account) to reach the vulnerable component, and the attack requires no user interaction. The exploit has been publicly disclosed via a Google Drive document referenced in the VulDB submission, though specific payload details are not fully documented in public sources (VulDB).

Impact

Successful exploitation could allow a high-privileged attacker to read, and potentially modify, files outside the web application's intended directory structure, resulting in low-level impacts to confidentiality, integrity, and availability. This could expose sensitive server-side configuration files, credentials, or application data, and may enable limited file manipulation. Because the exploit is publicly disclosed, the risk of opportunistic exploitation by authenticated attackers (e.g., compromised admin accounts) is elevated (GitHub Advisory, VulDB).

Exploitability

A proof-of-concept exploit has been publicly disclosed via a Google Drive link referenced in the VulDB submission, though no evidence of active in-the-wild exploitation has been reported as of the time of this report (GitHub Advisory). The EPSS score is approximately 0.079%–0.161% (37th percentile), indicating a relatively low but non-negligible probability of exploitation within 30 days. No threat actor attribution has been identified, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify OpenCart installations running version 4.1.0.3 using web fingerprinting tools (e.g., Wappalyzer, Shodan) or by checking the OpenCart admin panel version string.
  2. Obtain Admin Credentials: Gain access to a high-privileged (administrator) account through credential theft, phishing, brute force, or credential reuse — exploitation requires authentication.
  3. Navigate to Extension Installer: Log into the OpenCart admin panel and navigate to the Extension Installer Page, which invokes installer.php.
  4. Craft Malicious Path Input: Submit a manipulated file path containing traversal sequences (e.g., ../../) in the relevant input field or file upload parameter handled by installer.php.
  5. Access Out-of-Scope Files: The server processes the traversal sequence without proper sanitization, resolving the path to a location outside the restricted application directory, potentially exposing sensitive files such as configuration files or system files (VulDB, GitHub Advisory).

Indicators of compromise

  • Logs: Web server access logs showing requests to installer.php with URL-encoded or raw path traversal sequences (e.g., ../, %2e%2e%2f, ..%2f) in parameters or file upload fields.
  • File System: Unexpected access or modification timestamps on files outside the OpenCart web root (e.g., /etc/passwd, server configuration files, or parent directory files).
  • Network: Unusual outbound connections from the web server process following admin panel activity, which may indicate post-exploitation data exfiltration.
  • Application Logs: OpenCart admin audit logs showing Extension Installer activity from unfamiliar IP addresses or at unusual times.

Mitigation and workarounds

No official patch has been released by the OpenCart vendor as of the time of this report, and the vendor did not respond to the researcher's disclosure (GitHub Advisory). Recommended interim mitigations include: restricting administrative panel access to trusted IP addresses via firewall or web server configuration; applying the principle of least privilege to admin accounts; monitoring file system and web server access logs for path traversal patterns; and hardening file permissions on the OpenCart installation directory to prevent unauthorized file access. Organizations should monitor for an official patch from OpenCart and apply it promptly upon release (VulDB).

Community reactions

The vulnerability was assigned and published by VulDB and subsequently indexed by NVD, ENISA EUVD, and Red Hat CVE databases. No notable public commentary from prominent security researchers or significant media coverage has been identified beyond standard vulnerability database aggregation. The vendor's lack of response to the coordinated disclosure was noted in the advisory (GitHub Advisory, VulDB).

Additional resources


SourceThis report was generated using AI

Related OpenCart vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-47923CRITICAL9.3
  • OpenCart logoOpenCart
  • cpe:2.3:a:opencart:opencart
NoYesMay 10, 2026
CVE-2026-18412CRITICAL9.1
  • OpenCart logoOpenCart
  • cpe:2.3:a:opencart:opencart
NoNoAug 10, 2026
CVE-2021-47946MEDIUM6.9
  • OpenCart logoOpenCart
  • cpe:2.3:a:opencart:opencart
NoYesMay 10, 2026
CVE-2021-47953MEDIUM5.3
  • OpenCart logoOpenCart
  • cpe:2.3:a:opencart:opencart
NoYesMay 10, 2026
CVE-2026-5331LOW2
  • OpenCart logoOpenCart
  • cpe:2.3:a:opencart:opencart
NoNoApr 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management