CWE-23— Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.— MITRE CWE catalog
510 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-23page 10 of 11
- CVE-2026-55474MEDIUMCVSS 6.5EG 6.52026-07-10
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to t…
- CVE-2026-56196HIGHCVSS 8.8EG 8.82026-07-14
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
- CVE-2026-56794MEDIUMCVSS 6.5EG 6.52026-08-07
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for…
- CVE-2026-57871HIGHCVSS 7.1EG 7.12026-07-07
Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. This issue affects MicroRealEstate: through 1.0.0-alpha3.
- CVE-2026-57988HIGHCVSS 7.1EG 7.12026-07-03
Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-58413MEDIUMCVSS 6.1EG 6.12026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup path with `join(envDir, '.backups', backupId)` and only checks that this path exists. It …
- CVE-2026-58481MEDIUMCVSS 6.5EG 6.52026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks use raw string prefix tests. A sandbox …
- CVE-2026-58522MEDIUMCVSS 6.8EG 6.82026-07-03
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
- CVE-2026-59149MEDIUMCVSS 6.5EG 6.52026-07-09
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath in packages/commons-server/src/libs/server/server.ts with resolvedPath.startsWith(staticBas…
- CVE-2026-5966HIGHCVSS 8.1EG 8.12026-04-20
ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system.
- CVE-2026-59792CRITICALCVSS 9.8EG 9.82026-07-10
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
- CVE-2026-59832HIGHCVSS 7.7EG 7.72026-07-09
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath co…
- CVE-2026-59995MEDIUMCVSS 5.4EG 5.42026-07-08
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
- CVE-2026-59996MEDIUMCVSS 5.4EG 5.42026-07-08
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
- CVE-2026-60093MEDIUMCVSS 5.5EG 5.52026-08-24
Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-datalake …
- CVE-2026-61343HIGHCVSS 7.2EG 7.22026-07-09
LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template director…
- CVE-2026-62837MEDIUMCVSS 6.5EG 6.52026-08-11
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
- CVE-2026-62843MEDIUMCVSS 6.8EG 6.82026-07-15
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"…
- CVE-2026-63043HIGHCVSS 7.5EG 7.52026-08-20
Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pi…
- CVE-2026-63303MEDIUMCVSS 5.1EG 5.12026-07-28
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacke…
- CVE-2026-63490HIGHCVSS 7.5EG 7.52026-08-20
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader wit…
- CVE-2026-63509CRITICALCVSS 8.8EG 9.92026-08-20
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
- CVE-2026-6540HIGHCVSS 7.5EG 7.52026-07-30
Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes ar…
- CVE-2026-65810HIGHCVSS 7.8EG 7.82026-08-11
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-66881HIGHCVSS 8.1EG 8.12026-08-05
Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook can declare file_entries metadata, each entry ca…
- CVE-2026-66897CRITICALCVSS 9.9EG 9.92026-08-24
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target…
- CVE-2026-66906CRITICALCVSS 9.1EG 9.12026-08-24
Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob compone…
- CVE-2026-66907HIGHCVSS 7.5EG 7.52026-08-24
Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-google-storage consumer downlo…
- CVE-2026-67367HIGHCVSS 8.6EG 8.62026-09-08
A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1),…
- CVE-2026-70337HIGHCVSS 8.8EG 8.82026-08-11
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
- CVE-2026-72677HIGHCVSS 7.3EG 7.32026-08-13
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without re…
- CVE-2026-72948MEDIUMCVSS 6.7EG 6.72026-09-08
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
- CVE-2026-7404HIGHCVSS 7.3EG 7.32026-04-29
A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument det…
- CVE-2026-76424HIGHCVSS 7.2EG 7.22026-09-16
A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. This vulnerability is due to insufficient validation in file operations. An attacker cou…
- CVE-2026-76440CRITICALCVSS 9.8EG 9.82026-09-14
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review res…
- CVE-2026-77113MEDIUMCVSS 6.7EG 6.72026-08-20
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in …
- CVE-2026-77897HIGHCVSS 7.0EG 7.02026-09-08
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
- CVE-2026-78212HIGHCVSS 7.5EG 7.52026-08-24
4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files.
- CVE-2026-78254HIGHCVSS 7.4EG 7.42026-09-07
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite f…
- CVE-2026-79728MEDIUMCVSS 6.5EG 6.52026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this …
- CVE-2026-80130HIGHCVSS 8.8EG 8.82026-09-07
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vu…
- CVE-2026-80133HIGHCVSS 8.1EG 8.12026-09-07
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this …
- CVE-2026-8023HIGHCVSS 7.5EG 7.52026-06-29
Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, available when CONFIG_FILE_SYSTEM is enabled) that serves files from a configured root directory. Before this fix, both th…
- CVE-2026-8073HIGHCVSS 7.5EG 7.52026-05-19
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in the 'downloadZIP' function in all vers…
- CVE-2026-8100HIGHCVSS 8.6EG 8.62026-06-18
Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encoded paths during request processing. In …
- CVE-2026-8134HIGHCVSS 7.2EG 7.22026-05-21
Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing …
- CVE-2026-81838HIGHCVSS 7.1EG 7.12026-08-27
A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containi…
- CVE-2026-81849HIGHCVSS 8.8EG 8.82026-08-28
Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-Download…
- CVE-2026-8209MEDIUMCVSS 6.9EG 6.92026-05-09
Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction results in deletion of the file and a DOS condition. Successful e…
- CVE-2026-82765HIGHCVSS 8.1EG 8.12026-09-14
Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
Map vulnerabilities like CWE-23 to your infrastructure
EchelonGraph correlates every CVE — across CWE-23 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →