Security Advisory

CVE-2026-41951

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-11 09:32:21
Last updated 2026-05-11 12:43:07
Assigner jpcert
CVSS score 7.2
State PUBLISHED

Description

Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.