CVE-2026-5014 | elecV2 elecV2P up to 3.8.3 Wildcard /log/ path.join path traversal (Issue 200 / EUVD-2026-16947)
A vulnerability was found in elecV2 elecV2P up to 3.8.3. It has been declared as critical. The affected element is the function path.join of the file /log/ of the component Wildcard Handler. The manipulation results in path traversal.
This vulnerability was named CVE-2026-5014. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.