[Japanese]

JVNDB-2026-000132

a-blog cms vulnerable to path traversal

Overview

a-blog cms provided by appleple inc. contains the following vulnerability.
  • Path traversal (CWE-22) - CVE-2026-87727
You are affected by this vulnerability only when "Attaching files to emails addressed to the administrator" is enabled in the form settings.

hibiki moriyama of STNet, Incorporated reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 6.5 (Medium) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: Low
  • Availability Impact: None
CVSS v4 Severity
Base Metrics: 6.9 (Medium) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): None
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): Low
  • Integrity Impact (VI): Low
  • Availability Impact (VA): None
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
Affected Products


appleple inc.
  • a-blog cms versions 3.2.33 and earlier

Impact

Arbitrary files on the system may be read or deleted by a remote unauthenticated attacker.
Solution

[Update the Software]
Update the software to the latest version according to the information provided by the developer.

According to the developer, no update will be provided for versions 2.11 or earlier, as support for those versions has already ended. Therefore, users of those versions are recommended to upgrade to version 3.0 or later.

[Apply the Workaround]
The developer recommends applying the workaround until the product is updated.

For more details, refer to the information provided by the developer.
Vendor Information

appleple inc.
CWE (What is CWE?)

  1. Path Traversal(CWE-22) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-87727
References

  1. JVN : JVN#20829034
Revision History

  • [2026/09/11]
      Web page was published