A vulnerability was found in Microweber up to 2.0.20. It has been classified as problematic. Affected is the function normalize_path of the component Static File Controller. Performing a manipulation of the argument path results in path traversal.

This vulnerability is identified as CVE-2026-65694. The attack can be initiated remotely. There is not any exploit available.