A vulnerability classified as critical has been found in Phoca Commander Extension up to 6.1.3. Affected by this issue is some unknown functionality. This manipulation causes path traversal.

The identification of this vulnerability is CVE-2026-66493. It is possible to initiate the attack remotely. There is no exploit available.