CVE-2026-102119
Received Received - Intake

Path Traversal in Administrative Feature

Vulnerability report for CVE-2026-102119, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. This could potentially be leveraged to execute arbitrary code on the underlying system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal weakness in an optional administrative feature. It allows an authenticated admin to move files outside the feature's intended directory, potentially leading to arbitrary code execution on the system.

Detection Guidance

Since this is a path traversal vulnerability in an administrative feature, detection requires checking file system access patterns and administrative logs. Look for unusual file writes outside designated directories by authenticated admins. Review server logs for suspicious file operations or unexpected directory traversals in admin interfaces.

Impact Analysis

An attacker with admin access could exploit this to move malicious files to critical system locations, enabling remote code execution. This could lead to full system compromise, data theft, or denial of service.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to sensitive data or system resources. GDPR and HIPAA mandate strict access controls; a breach could result in legal penalties or data exposure.

Mitigation Strategies

Disable the non-default administrative feature if not in use. Restrict administrator access to only necessary personnel. Monitor file system changes and unauthorized directory access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102119. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart