Beveiligingsadvies

CVE-2026-5022

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-03-27 14:34:14
Laatst bijgewerkt 2026-03-27 15:10:20
Toegewezen door tenable
CVSS-score 6.3
Status PUBLISHED

Beschrijving

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by knowing (or guessing) the flow ID and file name.