A vulnerability was found in Microweber up to 2.0.20. It has been classified as problematic. Affected is the function
normalize_path of the component Static File Controller. Performing a manipulation of the argument path results in path traversal.
This vulnerability is identified as CVE-2026-65694. The attack can be initiated remotely. There is not any exploit available.