CVE-2026-8170
Received Received - Intake

Symbolic Link Path Traversal in ExtremeXOS CLI Utilities

Vulnerability report for CVE-2026-8170, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: ExtremeNetworks

Description

The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privilege boundary. An attacker with low-privilege CLI access can create a symbolic link that references a privileged filesystem location and then invoke the affected utilities to read, modify, or replace security-critical files outside of their authorized scope. Under certain conditions, this may enable escalation to root-level access and persistent modification of the device software stack. Exploitation is possible remotely by an attacker holding a low-privilege account, or locally via the serial console. Extreme would like to thank Hadrien Barral (UniversitΓ© Gustave Eiffel) and Georges-Axel Jaloyan (French Ministry of the Interior) for responsible disclosure of their findings.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
extreme extremexos *
extremenetworks extremexos *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the mv, cp, and rm file utilities in ExtremeXOS (EXOS) shell environment. These utilities fail to safely handle paths and symbolic links, allowing attackers with low-privilege CLI access to manipulate files outside their authorized scope by creating malicious symbolic links. This could lead to reading, modifying, or replacing security-critical files, potentially escalating privileges to root-level access.

Detection Guidance

This vulnerability involves unsafe path handling in ExtremeXOS file utilities (mv, cp, rm). To detect it, inspect symbolic links and file operations in the EXOS shell environment. Check for unexpected file modifications or accesses in privileged directories. No specific commands are provided in the context, but monitor for unauthorized changes to critical system files.

Impact Analysis

If you use ExtremeXOS devices, an attacker could exploit this to gain unauthorized access, modify system files, or escalate privileges to root. This may result in complete control over the device, data breaches, or persistent malicious changes to the software stack. Exploitation can occur remotely via low-privilege accounts or locally through the serial console.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, violating compliance requirements for GDPR, HIPAA, and other regulations. It may result in data breaches, loss of data integrity, or unauthorized disclosure, potentially leading to legal penalties, fines, or reputational damage.

Mitigation Strategies

Apply ExtremeXOS patches or updates provided by Extreme Networks to fix the path canonicalization and symbolic link handling issues in mv, cp, and rm utilities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8170. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart