CVE-2026-22799 | Emlog up to 2.6.1 REST API Endpoint index.php?rest-api=upload unrestricted upload (GHSA-p837-mrw9-5x5j / EUVD-2026-1995)
A vulnerability described as critical has been identified in Emlog up to 2.6.1. Affected by this issue is some unknown functionality of the file /index.php?rest-api=upload of the component REST API Endpoint. The manipulation results in unrestricted upload.
This vulnerability is identified as CVE-2026-22799. The attack can be executed remotely. There is not any exploit available.
A patch should be applied to remediate this issue.