Security Advisory

CVE-2026-82460

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-29 16:35:24
Last updated 2026-08-31 18:35:13
Assigner VulnCheck
CVSS score 9.8
State PUBLISHED

Description

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory.