External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 12 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks. | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ivanti
Published:
Updated: 2026-05-12T15:44:12.334Z
Reserved: 2026-05-06T16:56:11.386Z
Link: CVE-2026-8043
No data.
Status : Received
Published: 2026-05-12T15:16:17.153
Modified: 2026-05-12T15:16:17.153
Link: CVE-2026-8043
No data.
OpenCVE Enrichment
No data.
Weaknesses