CVE-2026-64966: ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor priv
infovulnerability
security
Summary
ATutor has a path traversal vulnerability (a flaw that lets attackers access files outside their intended directory) in its ZIP extraction feature. An attacker with instructor access can upload a crafted ZIP file to write executable files outside the extraction directory, potentially gaining RCE (remote code execution, where an attacker can run commands on a server) with web server privileges. The product is no longer supported and version 2.2.4 is confirmed vulnerable.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
August 20, 2026
Classification
Attack SophisticationModerate
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64966
First tracked: August 20, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 95%