PT-2026-58026 · Ivanti · Ivanti Xtraction
CVE-2026-14903
·
Published
2026-07-14
·
Updated
2026-07-16
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ivanti Xtraction versions prior to 2026.2.1
Description
A path traversal issue allows a remote authenticated attacker to read arbitrary files located outside the web root. Path traversal is a flaw that allows an attacker to access files and directories that are stored outside the web root folder by manipulating variables such as file paths.
Recommendations
Update to version 2026.2.1.
Fix
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ivanti Xtraction