CVE-2026-90445
An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traverse outside the destination directory, causing the extraction process to write files to arbitrary locations with the privileges of that process. This could allow an attacker to inject fabricated records into the system's stored data or tamper with application configuration.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- CWE
- CWE-22
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- CISA Malcolm
- CISA Malcolm
Weakness type
Related vulnerabilities
- CVE-2026-85706 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
- CVE-2026-49846 — libks has path traversal in kws HTTP parser via URI segment overflow
- CVE-2026-87910 — tarfile hardlink fallback ignores custom extraction filter rejection via None
- CVE-2026-87984 — An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an...
- CVE-2026-87983 — An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an...
- CVE-2026-87727 — a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an...
- CVE-2026-19991 — UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion
- CVE-2026-77807 — AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 11.0.4 - Unauthenticated Arbitrary File Read via 'user[name]' Parameter