CVE-2026-16219 is a path traversal vulnerability in Croogo CMS through version 4.0.7. The flaw affects the Admin File Manager component, specifically the FileManager::isEditable function in FileManager/src/Utility/FileManager.php. Improper validation of file path input allows an attacker to manipulate path values so that file operations are evaluated outside the intended directory boundaries. The issue is remotely exploitable and public exploit information is available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a defensive research PoC and lab package for CVE-2026-16219 affecting Croogo CMS Admin File Manager. It is not part of a common exploit framework. The repository contains: (1) a Bash HTTP PoC in poc/croogo_local_poc.sh, (2) verification and cleanup helpers, (3) a standalone PHP logic model in demo/path_authorization_demo.php, (4) documentation covering technical analysis, lab setup, detection, remediation, and references, and (5) illustrative patch material and tests. Main exploit capability: the Bash PoC performs an authenticated POST to Croogo's create-file admin endpoint and attempts to exploit a path-authorization failure so a FileManager-capable user can write outside the configured editable root. The repository describes the root cause as Croogo using Configure::check() instead of Configure::read() for FileManager.editablePaths, causing a Boolean to be used where a path list is expected and undermining the containment check. The practical result is an arbitrary file write primitive constrained by the permissions of the PHP/web-server account. The included payload is intentionally non-executable and fixed: it generates a timestamped .txt marker containing a CROOGO_CVE_2026_16219_SAFE_MARKER string and targets only /tmp/croogo-cve-2026-16219/. The PoC enforces strong guardrails: BASE must be exactly loopback 127.0.0.1 with optional port, no hostnames or alternate addresses are accepted, redirects are not followed, curl is forced to avoid proxies, and the script refuses to run without explicit lab acknowledgement. Authentication and CSRF bypass are not attempted; valid Cookie and X-CSRF-Token values must be supplied from a legitimate lab session. Repository structure is coherent and purposeful. README.md explains the vulnerability and safe usage. demo/path_authorization_demo.php models the bug without network access by showing a buggy path check returning ALLOWED for an outside path while a safe canonical separator-aware check returns DENIED. docs/technical-analysis.md explains the vulnerable data flow and impact. docs/remediation.md and patches/illustrative-hardening.patch show how to replace Configure::check() with Configure::read() and implement a safer realpath-based containment check. docs/detection.md provides log and filesystem review guidance. tests/test_guardrails.sh validates that the PoC remains loopback-only, does not leak secrets, and does not follow redirects. Overall, this is a real exploit repository but deliberately safety-constrained. It demonstrates authenticated arbitrary file write/path traversal authorization bypass against vulnerable Croogo File Manager instances in a local lab, with operational code for request delivery, verification, cleanup, and regression testing.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.