Security Advisory

CVE-2026-10621

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-02 14:03:35
Last updated 2026-06-02 19:27:51
Assigner certcc
CVSS score not scored
State PUBLISHED

Description

Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.