THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-73849 (CRITICAL 9.8) — Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote attacker can submit hostname, dbus

[NVD] CVE-2026-73849 (CRITICAL 9.8) — Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote attacker can submit hostname, dbus

lownvdPublished 2026-08-14

CVE-2026-73849 CVSS: 9.8 CRITICAL Published: 2026-08-14T18:19:09.987

Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote attacker can submit hostname, dbuser, dbpasswd, dbname, dbprefix, username, password

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73849