{"id":"CVE-2026-40526","summary":"Volmarg Personal Management System Path Traversal via get-file Endpoint","details":"Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET /public/get-file/{path} endpoint. The path route parameter is passed directly to file_get_contents() without canonicalization against a permitted base directory, enabling attackers to retrieve sensitive files accessible to the PHP-FPM worker process without using directory traversal sequences.","modified":"2026-08-30T03:30:24.292687027Z","published":"2026-08-27T13:12:50.291Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40526.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40526.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40526"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/volmarg-personal-management-system-path-traversal-via-get-file-endpoint"},{"type":"FIX","url":"https://github.com/Volmarg/personal-management-system/commit/a0443570e105ed4835ce57f3c0a3e33d5b77418c"},{"type":"FIX","url":"https://github.com/Volmarg/personal-management-system/commit/fb9d3679d5b28977ef59e61c3eed42bec602ed8b"},{"type":"PACKAGE","url":"https://github.com/Volmarg/personal-management-system"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/volmarg/personal-management-system","events":[{"introduced":"0"},{"fixed":"a0443570e105ed4835ce57f3c0a3e33d5b77418c"},{"fixed":"fb9d3679d5b28977ef59e61c3eed42bec602ed8b"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.0.4"}]}}],"versions":["v2.0.4","v2.0.3","v2.0.3b","v2.0.2","v2.0.1","v2.0.0","v1.4.65","v1.4.64","v1.4.63","v1.4.62","v1.4.61","v1.4.6","v1.4.52","v1.4.50","v1.4.46","v1.4.45","v1.4.44","v1.4.43","v1.4.42","v1.4.41","v1.4.4","v1.4.31","v1.4.30","v1.4.25","v1.4.23","v1.4.22","v1.4.21","v1.4.2","v1.4.1","v1.4.01","v1.4","1.31.1","v1.31","v1.3a.1","v1.3","v1.23","v1.21","v1.20.8.5","v1.20.8.4","v1.20.8.3","v1.20.8.2","v1.20.8.1","v1.20.8","v1.20.7","v1.20.6","v1.20.5","v1.20.4","v1.20.3","v1.20.2","v1.20.1","v1.20","1.19","v1.18.9","v1.18.8","v1.18.7","v1.18.6","v1.18.5","v1.18.4","v1.18.2","v1.18.1","v1.18","v1.17.7","v1.17.6","v1.17.5","v1.17.4","v1.17.3","v1.17.2","v1.17.1","v1.17","v1.15","v1.14","v1.13","v1.12","v1.11","v1.1","v1.01","v1.0","Beta1.4","Beta1.3","Beta1.2","beta1.1","beta1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40526.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}