Security Risk Category

Path Traversal Security Risks — Page 2

Published vulnerability pages connected to Path Traversal. Each page keeps one canonical URL and focused remediation guidance.

167 published Path Traversal risks

Path Traversal risks

Showing 37–72 of 167 published risks.

high

CVE-2026-56623 Apache MINA SSHD vulnerability

Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git server implemented with Apache MINA SSHD component sshd-git and running on Windows could allow an authenticated remote user access to git repositories outside of the configured server-side root directory. The path validation applied for CVE-2026-48827 in Apache MINA SSHD 2.18.0 and 3.0.0-M4 was partly ineffective for Servers running on Windows. Applications are affected if they use org.apache.sshd:sshd-git to implement a git server and run on Windows. Applications not using sshd-git or not running on Windows are not affected. Users are advised to upgrade affected applications to Apache MINA SSHD 2.19.0, which fixes the issue. The issue also is present in the pre-release milestones 3.0.0-M1 to 3.0.0-M4 for a new upcoming new major version 3.0.0. Again, applications are affected only if they use sshd-git and run on Windows. Upgrade affected applications to 3.0.0-M5.

CVE-2026-56623javawindowsnetwork-securitypath-traversal

Updated Jul 21, 2026

high

CVE-2026-56452 Apache MINA SSHD vulnerability

Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places. The issue affects only * applications that use no longer supported Apache MINA SSHD versions < 2.0.0 and use the SCP functions to receive files, * or applications using sshd-scp in Apache MINA SSHD >= 2.0.0 to receive files. Applications using Apache MINA SSHD >= 2.0.0 not using sshd-scp are not affected. The issue is fixed in Apache MINA 2.19.0 and 3.0.0-M5. Affected applications are advised to upgrade to these versions.

CVE-2026-56452javanetwork-securitypath-traversal

Updated Jul 21, 2026

medium

CVE-2026-47144 shamefile vulnerability

Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame next` allows an attacker-controlled `shamefile.yaml` to disclose contents of files outside the repository, one line at a time, to the terminal of a user who runs the command. See patch commit for technical details. The issue is fixed in 0.1.7. Upgrade to either 0.1.7 or later versions to incorporate the patch. As a workaround, do not run `shame next` against untrusted `shamefile.yaml`. Use `shame me --dry-run` for CI validation.

CVE-2026-47144path-traversal

Updated Jul 21, 2026

highEPSS 0.006

CVE-2026-48310 experience manager vulnerability

Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48310path-traversalfile-write

Updated Jul 19, 2026

mediumEPSS 0.008

Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and above, to delete arbitrary directories on the server, which can result in loss of data and availability.

CVE-2026-15457wordpresspath-traversalfile-deletion

Updated Jul 19, 2026

mediumEPSS 0.005

Ninja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path Traversal

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to write .xls/.xlsx files to arbitrary locations on the server, which can be used to stage further attacks.

CVE-2026-15160wordpressauthorization-bypasspath-traversal

Updated Jul 19, 2026

highEPSS 0.003

CVE-2026-60114 sustainable irrigation platform vulnerability

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files with unvalidated keys used to construct file paths. Attackers can exploit the lack of key validation in the JSON restore process, combined with the absence of a required passphrase in the default configuration or the default passphrase 'opendoor', to write arbitrary JSON files outside the intended data directory.

CVE-2026-60114path-traversal

Updated Jul 17, 2026

highEPSS 0.006

CVE-2026-40400 windows 10 1607 vulnerability

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

CVE-2026-40400windowspath-traversal

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-45496 visual studio code vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-45496microsoftpath-traversal

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-50364 windows 10 21h2 vulnerability

Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.

CVE-2026-50364windowspath-traversal

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-58636 pc manager vulnerability

Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-58636path-traversal

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48350 animate vulnerability

Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to access sensitive files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48350remote-code-executionpath-traversal

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-54572 rclone vulnerability

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.

CVE-2026-54572path-traversal

Updated Jul 17, 2026

mediumEPSS 0.001

CVE-2026-59732 rclone vulnerability

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path components such as ../, allowing creation or overwrite of sibling objects in the same bucket or path scope. This issue is fixed in version 1.74.4.

CVE-2026-59732path-traversal

Updated Jul 17, 2026

highEPSS 0.005

CVE-2026-59733 rclone vulnerability

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4.

CVE-2026-59733idorpath-traversal

Updated Jul 17, 2026

mediumEPSS 0.001

CVE-2026-61859 imagemagick vulnerability

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.

CVE-2026-61859path-traversal

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-20146 identity services engine passive identity connector vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.&nbsp; This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.

CVE-2026-20146path-traversalfile-writefile-deletion

Updated Jul 17, 2026

criticalEPSS 0.067

CVE-2026-48318 in Adobe ColdFusion

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48318web-applicationinformation-disclosurepath-traversalfile-write

Updated Jul 16, 2026

criticalEPSS 0.009

CVE-2026-48319 in Adobe ColdFusion

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48319web-applicationremote-code-executionpath-traversal

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-48338 in Adobe ColdFusion

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48338web-applicationinformation-disclosurepath-traversalfile-write

Updated Jul 16, 2026

medium

CVE-2026-26032 in Apache Ivy

The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an Ant script, which is stored in a subdirectory of the configured "buildRoot" directory. This subdirectory is calculated based on modules coordinates, like the organisation, name or version. If one of the coordinates contains "../" sequences - which are valid characters for Ivy coordinates in general- it is possible to break out of the configured "buildRoot" directory where other files can be overwritten. In order to exploit this vulnerability an attacker needs to have access to a packager repository and add or modify the coordinates in ivy.xml files to have such "../" sequences. Users of Apache Ivy 2.0.0 to 2.5.3 (inclusive) should upgrade to Ivy 2.6.0.

CVE-2026-26032javasupply-chainpath-traversalfile-write

Updated Jul 16, 2026

high

Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter

The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the targeted form to not enforce login (so publicly accessible), which allows the unauthenticated attacker to reach the process_send_resume_link endpoint and supply an arbitrary recipient email address to receive the traversal-retrieved file as a notification attachment.

CVE-2026-12997wordpressinformation-disclosurepath-traversalfile-write

Updated Jul 16, 2026

lowEPSS 0.002

CVE-2026-41579 runc /dev Symlink Host File Modification Vulnerability

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when setting up the container rootfs, setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a filepath.Join string which allow an image with /dev as a symlink to trick runc into deleting files called ptmx on the host or creating a hardcoded set of symlinks with specific names and targets in an arbitrary pre-existing host directory. This issue is not exploitable under Docker, because Docker creates a top-level read-only layer that masks any malicious /dev symlink present in the container image — unlike some other Linux container tooling, whose higher-level runtimes built on runc remain exposed to exploitation via a malicious image. This issue has been fixed in versions 1.3.6, 1.4.3 and 1.5.0.

CVE-2026-41579linuxcloud-securitydevopssupply-chain

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-53906 MyComplianceOffice Path Traversal Information Disclosure Vulnerability

MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the filename parameter allows writing files to arbitrary locations as well as indirect disclosure of absolute server paths through error messages. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

CVE-2026-53906microsoftweb-applicationinformation-disclosurepath-traversal

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-61858 ImageMagick APNG Policy Bypass Vulnerability

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.

CVE-2026-61858input-validationpath-traversalfile-write

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-56260 Crawl4AI Arbitrary File Write Vulnerability

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.

CVE-2026-56260pythonapi-securitydenial-of-servicepath-traversal

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-55469 in Snipe-IT

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing deletion of arbitrary...

CVE-2026-55469phpweb-applicationpath-traversalfile-deletion

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-57211 in RabbitMQ Server

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management...

CVE-2026-57211windowsnetwork-securitypath-traversalssrf

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-59839 in FortiProxy

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM...

CVE-2026-59839network-securityremote-code-executionpath-traversal

Updated Jul 15, 2026

mediumEPSS 0.007

CVE-2026-54108 in Microsoft SharePoint Server

External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-54108windowsmicrosoftweb-applicationpath-traversal

Updated Jul 15, 2026

criticalEPSS 0.006

CVE-2026-41041 in Apache Gravitino

URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue.

CVE-2026-41041javaapi-securityinput-validationpath-traversal

Updated Jul 15, 2026

mediumEPSS 0.001

CVE-2026-15681 in AnyDesk

AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of screen recording files. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26591.

CVE-2026-15681denial-of-servicepath-traversalfile-write

Updated Jul 15, 2026

mediumEPSS 0.001

CVE-2026-15682 in AnyDesk

AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Send Support Information feature. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26645.

CVE-2026-15682denial-of-servicepath-traversalfile-write

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62189 in OpenClaw

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization boundaries when the feature is enabled and reachable.

CVE-2026-62189npmauthorization-bypasspath-traversalfile-write

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-8384 in Eclipse Jetty

In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served). However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path.

CVE-2026-8384javaweb-applicationpath-traversal

Updated Jul 15, 2026

medium

CVE-2026-49488 in Apache OpenMeetings

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including credentials and secrets, via a crafted download request. Users are recommended to upgrade to version 9.1.0, which fixes the issue.

CVE-2026-49488javaweb-applicationinformation-disclosurepath-traversal

Updated Jul 15, 2026