CVE-2026-8326
Deferred Deferred - Pending Action
Path Traversal in Remote Spark SparkView

Publication date: 2026-05-29

Last updated on: 2026-05-29

Assigner: Switzerland Government Common Vulnerability Program

Description
Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection.Β Β Depending on implementation, the vulnerability can be exploited by an unauthenticated attacker. This issue affects SparkView: before build 1127.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-29
Last Modified
2026-05-29
Generated
2026-05-29
AI Q&A
2026-05-29
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
remotespark sparkview to 1127 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a path traversal flaw in Remote Spark's SparkView component, specifically in the RDP drive redirection feature. It allows an attacker to read and write arbitrary files in all directories on the system with root privileges.

Because of this, the attacker can execute remote code (RCE) on the affected system. The vulnerability can be exploited by an unauthenticated attacker depending on the implementation.

The issue affects SparkView versions before build 1127.


How can this vulnerability impact me? :

This vulnerability can have severe impacts because it allows an attacker to execute arbitrary code with root privileges on the affected system.

  • An attacker could gain full control over the system.
  • Sensitive files can be read or modified without authorization.
  • It can lead to data breaches, system compromise, and disruption of services.
  • Since exploitation can be done without authentication, the risk is higher.

Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart