PT-2026-21660 · Unknown · Hummerrisk

·

CVE-2026-3067

·

Published

2026-02-24

·

Updated

2026-02-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HummerRisk versions up to 1.5.0
Description A path traversal issue exists in HummerRisk. The issue affects the extractTarGZ/extractZip function within the hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/utils/CommandUtils.java file, part of the Archive Extraction component. This manipulation can be exploited remotely. The details of the issue have been publicly disclosed. The vendor was informed of the disclosure but did not respond.
Recommendations Versions prior to 1.5.1 should be updated. As a temporary workaround, consider restricting access to the extractTarGZ/extractZip function until a patch is available.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3067

Affected Products

Hummerrisk