CVE-2026-88940
knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify targets for further exploitation.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- CWE
- CWE-22
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- knowns-dev knowns
Weakness type
Related vulnerabilities
- CVE-2026-77807 — AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 11.0.4 - Unauthenticated Arbitrary File Read via 'user[name]' Parameter
- CVE-2026-49836 — psd-tools: arbitrary file write via smart-object filename
- CVE-2026-80424 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-45767 — Suricata datasets: save to absolute filename can be bypassed when combined with load command
- CVE-2026-81540 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-81551 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-81554 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-82100 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software