CVE-2026-1186
Unknown
Unknown - Not Provided
Path Traversal in EAP Legislator Zipx Extraction Enables Arbitrary File Write
Publication date: 2026-02-02
Last updated on: 2026-02-02
Assigner: CERT.PL
Description
Description
EAP Legislator is vulnerable to Path Traversal in file extraction functionality. Attacker can prepare zipx archive (default file type used by the Legislator application) and choose arbitrary path outside the intended directory (e.x. system startup)Β where files will be extracted by the victim upon opening the file.
This issue was fixed in version 2.25a.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| abcp | legislator | to 2.25 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-22 | The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. |