๐Ÿ” CVE Alert

CVE-2026-62278

HIGH 8.1

LubeLogger: Path Traversal in HandleTranslationFileUpload Allows Authenticated Users to Write Files Outside Data Directory

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authenticated non-administrative users could reach HandleTranslationFileUpload and influence the name passed from Controllers/FilesController.cs to RenameFile in Helper/FileHelper.cs. RenameFile constructed newFilePath with string replacement and moved the uploaded file without verifying the resolved absolute path remained under the web root or data directory. A crafted upload name could therefore move an uploaded file outside the intended storage directory, enabling unauthorized file placement or overwrite with the privileges of the application process. This issue is fixed in version 1.6.8.

CWE CWE-22
Vendor hargata
Product lubelog
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for hargata lubelog

Be the first to know when new high vulnerabilities affecting hargata lubelog are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

hargata / lubelog
< 1.6.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/hargata/lubelog/security/advisories/GHSA-qm5x-mmwx-q7rm github.com: https://github.com/hargata/lubelog/issues/1398 github.com: https://github.com/hargata/lubelog/pull/1395 github.com: https://github.com/hargata/lubelog/commit/c8d5888ebc69e6a163e33f36200233ec845e5c57 github.com: https://github.com/hargata/lubelog/releases/tag/v1.6.8