Skip to main content
Vulnerability Database/CVE-2026-104478

CVE-2026-104478: Formwork Path Traversal Vulnerability

CVE-2026-104478 is a path traversal vulnerability in Formwork CMS that allows authenticated users to read or delete arbitrary files outside the backup directory. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-104478 Overview

CVE-2026-104478 is a path traversal vulnerability [CWE-22] in Formwork versions prior to 2.3.13. The flaw resides in the BackupController component of the administrative panel. Authenticated users holding backup download or delete permissions can supply a base64-encoded, backslash-separated traversal payload. On Linux systems, this payload bypasses PHP's basename() sanitization and resolves outside the backup directory. Successful exploitation allows attackers to read or delete arbitrary files accessible to the web server process.

Critical Impact

Authenticated panel users can read or delete arbitrary files on the host, exposing configuration data, credentials, and site integrity.

Affected Products

  • Formwork CMS versions before 2.3.13
  • Deployments running on Linux where backslashes are treated as valid filename characters
  • Installations exposing the panel BackupController download and delete routes

Discovery Timeline

  • 2026-10-03 - CVE-2026-104478 published to the National Vulnerability Database
  • 2026-10-05 - Last updated in NVD database

Technical Details for CVE-2026-104478

Vulnerability Analysis

Formwork's BackupController accepts a backup file identifier through a user-controlled parameter. The controller decodes the base64 input and passes the result to PHP's basename() function to strip directory components. On Linux, basename() only treats forward slashes as directory separators. Backslashes are preserved as valid filename characters.

An attacker crafts a payload such as ..\..\..\etc\passwd, base64-encodes it, and submits it to the download or delete endpoint. The sanitization routine returns the string unchanged. The controller then concatenates the attacker string with the backup directory path and passes it to the filesystem layer. The filesystem call interprets the backslashes as part of a valid path, enabling access outside the intended directory.

Root Cause

The root cause is reliance on basename() for filename sanitization without accounting for separator semantics across platforms. The maintainers introduced a dedicated Path utility that normalizes both / and \ separators before extracting the trailing component.

Attack Vector

Exploitation requires an authenticated panel account with backup download or delete permission. The attacker sends an HTTP request to the backup endpoint with a base64-encoded backslash-traversal string. Read access exposes sensitive files such as configuration data and credential stores. Delete access can corrupt or destroy site data and administrative artifacts.

php
// Patch excerpt from formwork/src/Panel/Controllers/BackupController.php
 use Formwork\Router\RouteParams;
 use Formwork\Utils\Date;
 use Formwork\Utils\FileSystem;
-use RuntimeException;
+use Formwork\Utils\Path;

 final class BackupController extends AbstractController
 {
// Source: https://github.com/getformwork/formwork/commit/89e7821a6fcee89474cd401b3dde0c1dccb0687f
php
// Patch excerpt from formwork/src/Utils/Path.php introducing separator-aware helpers
public static function dirname(string $path, string $separator = self::DEFAULT_SEPARATOR): string
{
    if (!self::isSeparator($separator)) {
        throw new InvalidArgumentException('$separator must be a valid directory separator');
    }
    $dirname = dirname(str_replace('\\', '/', $path));
    return $separator === '/'
        ? $dirname
        : str_replace('/', $separator, $dirname);
}
// Source: https://github.com/getformwork/formwork/commit/89e7821a6fcee89474cd401b3dde0c1dccb0687f

Detection Methods for CVE-2026-104478

Indicators of Compromise

  • HTTP requests to Formwork panel backup download or delete routes containing base64 parameters that decode to strings with ..\ sequences
  • Web server access logs showing successful 200 responses for backup endpoints with unexpectedly large or unusual response sizes
  • Unexpected deletions of files outside the Formwork backups/ directory, correlated with authenticated panel sessions

Detection Strategies

  • Decode base64 query or body parameters sent to the Formwork panel and alert on decoded content containing ..\, ..%5c, or mixed separator traversal sequences
  • Audit Formwork panel user activity for backup operations performed by accounts that do not normally administer backups
  • File integrity monitoring on directories adjacent to the Formwork installation to flag unauthorized read or delete activity by the PHP process

Monitoring Recommendations

  • Enable verbose logging on the Formwork panel and forward authentication and backup events to a central SIEM
  • Correlate panel session identifiers with filesystem access logs on the web server host
  • Alert on any PHP-FPM or web server process accessing sensitive paths such as /etc/passwd, /etc/shadow, or application configuration files

How to Mitigate CVE-2026-104478

Immediate Actions Required

  • Upgrade Formwork to version 2.3.13 or later, which replaces basename() with the separator-aware Path utility
  • Review and reduce the number of panel accounts holding backup download and delete permissions
  • Rotate credentials and secrets stored in files that may have been readable by the web server process

Patch Information

The fix is published in commit 89e7821 in the Formwork repository. It introduces a new Formwork\Utils\Path class with dirname() and basename() implementations that normalize both / and \ separators before extracting path components. Additional context is available in the VulnCheck advisory for Formwork.

Workarounds

  • Restrict panel access to trusted networks using a reverse proxy or firewall allow-list until the upgrade is applied
  • Temporarily revoke backup download and delete permissions from all non-essential panel users
  • Deploy a web application firewall rule that decodes base64 parameters on backup endpoints and blocks requests containing backslash traversal sequences
bash
# Example WAF-style ModSecurity rule blocking backslash traversal in base64 payloads
SecRule ARGS "@rx (?:\.\.(?:%5c|\\))" \
    "id:1046478,phase:2,deny,status:403,msg:'Formwork CVE-2026-104478 traversal attempt',\
     t:none,t:base64Decode,t:lowercase"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.