Security Advisory

CVE-2026-56845

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-04 00:43:48
Last updated 2026-08-04 15:04:12
Assigner hackerone
CVSS score not scored
State PUBLISHED

Description

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.