Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
CVE-2026-38739 is a low severity vulnerability with a CVSS score of 0.0. No known public exploits at this time.
Very low probability of exploitation
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
NB: All tags and branches in this repository are past their end of life, so the vulnerability will not be fixed. The advisory is posted on the request of the researcher, for the information of anyone who might still use this software.
There is a security vulnerability in eZ Publish Legacy, affecting the dfscleanup.php script and the _getFileList function of the eZDFSFileHandlerMySQLiBackend class (kernel/private/classes/clusterfilehandlers/dfsbackends/mysqli.php). The vulnerability allows an attacker with local shell access and sufficient privileges to run dfscleanup.php to perform a union-based SQL injection against the eZ Publish MySQL database, potentially exposing sensitive data such as user credentials.
It is known to affect the branch 2019.03, and it may well affect other branches.
The issue was found and reported by security auditor Timothé Ridel from Advens: https://www.advens.com/
None, the software is past its end of life.
None.
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.