A vulnerability classified as critical has been found in CubeCart up to 6.5.x. This issue affects some unknown processing. This manipulation causes path traversal.
This vulnerability is handled as CVE-2026-35496. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.