CVE-2026-48820
Description
CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11.
Summary dbcve.org
CakePHP's View::_getElementFileName() method fails to validate that resolved element paths stay within allowed application/plugin view template directories. This allows path traversal via crafted element names (e.g., using ../../ sequences) to include arbitrary PHP files on the server, resulting in potential local file inclusion.
Mitigation
Upgrade CakePHP to patched versions (5.3.6, 5.2.13, 5.1.7, 4.6.4, or 4.5.11). If immediate patching is not feasible, implement strict input validation on element name parameters to reject path traversal sequences.