PT-2026-58062 · Cpan · Dbd::File

CVE-2026-15392

·

Published

2026-07-14

·

Updated

2026-09-07

CVSS v3.1

7.7

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions DBD::File versions prior to 1.651
Description The software fails to verify if a table file is a symbolic link to an untrusted location. The complete table name() function constructs the absolute path to the table file without checking for symbolic links. Consequently, a link placed within the data directory can point to files outside the configured f dir and f dir search directories, allowing users of file-based drivers to read or write files outside the intended data directory.
Recommendations Update to version 1.651 or later.

Exploit

Fix

DoS

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92424
CVE-2026-15392
ECHO-AAC2-EBA6-686E
GHSA-MH3J-XWF4-JRQW
OPENSUSE-SU-2026:11298-1
OPENSUSE-SU-2026:21412-1
SUSE-SU-2026:22845-1
SUSE-SU-2026:22926-1
SUSE-SU-2026:3283-1
SUSE-SU-2026:3415-1
SUSE-SU-2026:3461-1

Affected Products

Dbd::File