CVE 8.6 HIGH

Path Traversal in EAP Legislator_CVE-2026-1186

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L

Description

EAP Legislator is vulnerable to Path Traversal in file extraction functionality. Attacker can prepare zipx archive (default file type used by the Legislator application) and choose arbitrary path outside the intended directory (e.x. system startup)Β where files will be extracted by the victim upon opening the file.
This issue was fixed in version 2.25a.

Basic Information

ID CVE-2026-1186
Source CERT-PL
Published Feb 2, 2026 at 13:59

Affected Product

Vendor ABC PRO SP. Z O.O.
Product EAP Legislator
Affected Versions ABC PRO SP. Z O.O. EAP Legislator 0

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.