CVE-2026-108158
Deferred Deferred - Pending Action

Path Traversal in plugNmeet Server

Vulnerability report for CVE-2026-108158, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

plugNmeet Server through 2.5.2 contains a path traversal vulnerability in the whiteboard conversion endpoint that allows any meeting participant to read server files via crafted filePath values. Attackers can supply ../ sequences so text or office documents are converted into page images, then fetch them unauthenticated through /download/uploadedFile/.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mynaparrot plugNmeet-server 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in plugNmeet Server through version 2.5.2 affecting the /api/whiteboard/convert endpoint. Any meeting participant can exploit crafted filePath values containing ../ sequences to read arbitrary server files. The server converts manipulated files into page images and stores them in the upload directory. These files can then be downloaded without authentication via the /download/uploadedFile/ endpoint.

Detection Guidance

Check for unauthorized access to sensitive files via the /api/whiteboard/convert endpoint. Monitor logs for requests containing ../ sequences in filePath parameters. Inspect /download/uploadedFile/ endpoints for unauthenticated downloads of converted files.

Impact Analysis

Attackers could access sensitive server files including configuration files, user data, or other confidential information. This could lead to unauthorized data exposure, potential system compromise, or denial of service if files are corrupted during conversion. The low attack complexity and required privileges make exploitation feasible for any meeting participant.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to protected health information under HIPAA or personal data under GDPR. Organizations using affected versions may face regulatory penalties, data breach notifications, and reputational damage due to inadequate file access controls and insufficient authorization mechanisms.

Mitigation Strategies

Upgrade plugNmeet-server to a version beyond 2.5.2. Validate file paths in the /api/whiteboard/convert endpoint to prevent directory traversal. Restrict access to /download/uploadedFile/ endpoints with proper authorization checks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108158. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart