← Browse

CVE-2026-82460

Medium

Elevated severity or exploit probability.

CVSS base
9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
1.2%
67.1th percentile
CISA KEV
Not listed
Weakness / dates
CWE-22
Published 2026-08-29 · modified 2026-08-31

Description

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory.

References

Official: NVD · CVE.org