# CVE-2026-46687

## Summary

- **CVE ID:** CVE-2026-46687
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-24, CWE-98
- **Published:** Jul 16, 2026
- **Last Modified:** Jul 16, 2026

## Description

Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, and log_controller.php later checks file_exists and calls include View::getView($template), allowing an authenticated author to include an arbitrary local .php file when an article is viewed. No fixed version is currently identified.

## Affected Products

- emlog — emlog (<= 2.6.13)

## References

- [CNA](https://github.com/emlog/emlog/security/advisories/GHSA-9h6g-q584-9vfg)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.44%
- **EPSS Percentile:** 36.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._