SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-16653

MEDIUM · CVSS 5.3 EPSS 0.48% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

A path traversal vulnerability exists in the Public Folder Handler of boazsegev facil.io versions up to 0.7.58, specifically in the http_sendfile2 function. This flaw allows remote attackers to manipulate file paths, potentially leading to unauthorized file access. Organizations using affected versions should prioritize remediation, as public exploit code is available.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16653
Severity
MEDIUM
CVSS
5.3
EPSS
0.48%

Original NVD Description

A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.