Security Advisory

CVE-2026-22102

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-13 09:10:58
Last updated 2026-07-16 15:41:06
Assigner DIVD
CVSS score 9.3
State PUBLISHED

Description

A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in the Content-Disposition header without verification. This can be used to cause a denial of service by overwriting system files, or remote-code-execution by overwriting shell-scripts which execution can be triggered through other means.