Skip to content
COOEY

EXPOSURES › CVE-2026-82460

CVE-2026-82460

CRITICAL
DETAIL
SourceNVD · cve Published2026-08-29 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-82460 ↗
SHAME 65/100 unpatchedexploited-in-wild

Cloud Commander before 19.20.2 allows attackers to read, write, move, or copy files outside the configured root directory via directory traversal in REST file-operation and markdown endpoints.

This directory traversal flaw lets attackers escape the intended file system boundary, enabling data exfiltration, file tampering, or system compromise. DIB organizations must ensure their Cloud Commander deployments are patched to version 19.20.2 or later to prevent unauthorized access to sensitive data and maintain compliance with NIST 800-171 controls on access control and system integrity.

Shame score — A critical directory traversal vulnerability with a CVSS score of 9.8 that allows attackers to read, write, move, or copy files outside the configured root directory, representing a severe avoidable failure in path validation.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.