CVE-2026-2328
Received Received - Intake
Path Traversal in Backend Components Allows Remote Data Exposure

Publication date: 2026-03-30

Last updated on: 2026-03-30

Assigner: CERT VDE

Description
An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their intended scope via path traversal, resulting in exposure of sensitive information.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-30
Last Modified
2026-03-30
Generated
2026-06-16
AI Q&A
2026-03-30
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
wago device_sphere to 1.2.2 (exc)
wago solution_builder to 2.4.2 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-790 The product receives data from an upstream component, but does not filter or incorrectly filters special elements before sending it to a downstream component.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-2328 is a vulnerability in WAGO Device Sphere and WAGO Solution Builder that allows an unauthenticated remote attacker to exploit insufficient input validation through a path traversal attack.

This means the attacker can access backend components beyond their intended scope by manipulating input paths, which bypasses normal security restrictions.

As a result, sensitive information may be exposed even though system integrity and availability are not affected.

Impact Analysis

This vulnerability can lead to unauthorized exposure of sensitive information stored in backend components of affected WAGO products.

Since the attacker does not need to be authenticated, the risk of data leakage is significant.

However, the vulnerability does not impact the integrity or availability of the system, meaning it does not allow modification or disruption of services.

Mitigation Strategies

To mitigate the CVE-2026-2328 vulnerability, update your affected software to the fixed versions.

  • Update WAGO Device Sphere to version 1.2.2 or later.
  • Update WAGO Solution Builder to version 2.4.2 or later.
Compliance Impact

This vulnerability allows an unauthenticated remote attacker to access backend components beyond their intended scope via path traversal, resulting in exposure of sensitive information.

Exposure of sensitive information can lead to non-compliance with common standards and regulations such as GDPR and HIPAA, which require protection of personal and sensitive data.

Therefore, if exploited, this vulnerability could cause violations of data protection requirements mandated by these regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-2328. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart