PT-2026-39201 · Unknown · Solidcam-Gppl-Ide

·

CVE-2026-42213

·

Published

2026-05-08

·

Updated

2026-05-09

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SolidCAM-GPPL-IDE versions 1.0.0 through 1.0.1
Description The GpplDocumentLinkHandler resolves the filename directive in GPPL postprocessor files into clickable links. The handler accepts arbitrary absolute, relative, UNC, and subfolder paths, calling File.Exists to determine if a link should be rendered. This allows for information disclosure through path probing and NTLM hash leaks via UNC path probing.
Recommendations Update to version 1.0.2.

Exploit

Fix

Path traversal

SSRF

Information Disclosure

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42213
GHSA-XVPX-9P39-G62M

Affected Products

Solidcam-Gppl-Ide