CVE 9.6 CRITICAL

CVE-2026-8043_CVE-2026-8043

9.6 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Description

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.

Basic Information

ID CVE-2026-8043
Source ivanti
Published May 12, 2026 at 14:11
Modified May 12, 2026 at 15:44

Affected Product

Vendor ivanti
Product Xtraction
Version 2026.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.