A vulnerability was found in Intelliants Subrion CMS up to 4.2.1. It has been rated as problematic. The impacted element is the function
unlink of the component Admin Panel File Deletion Endpoint. This manipulation causes path traversal.
This vulnerability is tracked as CVE-2026-72604. The attack is possible to be carried out remotely. No exploit exists.