SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-52349

HIGH · CVSS 7.8 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

A directory traversal vulnerability in Menyoo 2.0 prior to commit 729aa48 allows local attackers to execute arbitrary code through various file management functions, including those related to saving and renaming files. This poses a significant risk as it can lead to unauthorized access and manipulation of system files. Users of affected versions should prioritize applying the update to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-52349
Severity
HIGH
CVSS
7.8
EPSS
0.25%

Original NVD Description

Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary code via the Spooner file management, VehicleSpawner save/folder/rename functionality, WeaponOptions save/folder/rename functionality, PedComponentChanger create folder/createfile/rename functionality.