CVE-2026-73849Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote attacker can submit hostname, dbuser, dbpasswd, dbname, dbprefix, username, password, and email values to cause file_put_contents('config.php', $config) to overwrite the configuration with attacker-controlled database settings and create a new administrator account. No fixed version is available as of this review.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-14); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-14: 1Mentions · 2026-08-15: 1Technical Details · 2026-08-14: 1Technical Details · 2026-08-15: 108-1408-15
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • NewNormal Security@NewScanTeam
    Disclosure

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 15 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🖥️ Unauthenticated AI memory server — everything an assistant was told to remember is readable, and rewritable, by anyone who can reach the port (mcp-memory-service CVE-2026-50027) 🖥️ Unauthenticated database SQL endpoint — arbitrary SELECT, INSERT and DROP on every table, no credential (CrateDB) 🔓 Unfinished CMS installer left reachable — whoever loads the page first picks the admin password and owns the server (WordPress, as seen in Emlog CVE-2026-73849) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #ExposedInterface #CSO #REDTEAM

    Post summary

    The post announces three newly discovered CVEs with brief technical details of each vulnerability but does not disclose PoCs, exploits, patches, or evidence of active exploitation.

    0000053
    5 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-73849 Emlog install.php Overwrites Configuration and Creates Admin Acco... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73849 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE‑2026‑73849, noting that Emlog's install.php can overwrite configuration and create an admin account, and provides a link to additional details on vulmon.com.

    00000105
    4.1K followersView on X

Explore more