< ciso
brief />
Tag Banner

All news with #arbitrary file read tag

24 articles

Critical Atlassian Data Center Arbitrary File Access

πŸ›‘οΈ Atlassian has disclosed a critical arbitrary file access vulnerability (CVE-2026-21589, CVSS 9.3) affecting multiple Data Center products including Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye. The flaw allows unauthenticated attackers to retrieve specific files from the web application root if they know the exact path and filename. Atlassian released patches for impacted versions and recommends temporary mitigations such as removing instances from the public internet, deploying WAF rules, and applying Tomcat or urlrewrite.xml protections. Telemetry shows early exploitation attempts from a few IPs, and security researchers warn rapid scanning and mass exploitation are likely following public technical details.
read more β†’

Critical Atlassian flaw impacts eight enterprise products

πŸ”’ A critical arbitrary file access vulnerability, CVE-2026-21589 (9.3), affects eight Atlassian Data Center products and allows unauthenticated attackers to read files in the web app root. Atlassian urges immediate patching to fixed releases and offers limited mitigations (WAF rules, Tomcat RewriteValve, urlrewrite.xml) for those that cannot upgrade. Customers should isolate internet-facing instances, search logs for traversal patterns, and rotate exposed credentials if compromise is suspected.
read more β†’

Atlassian warns of critical arbitrary file-access flaw

⚠️ Atlassian has disclosed CVE-2026-21589, a critical arbitrary file-access vulnerability affecting multiple self-hosted Data Center products including Confluence, Jira, and Bitbucket. An unauthenticated attacker can access specific files within an application's web root if they know the exact filename and path, though directory listing is not possible. Atlassian released fixed versions and urges immediate patching; cloud instances were auto-patched. Temporary mitigations and detailed configuration steps are provided for administrators unable to patch immediately.
read more β†’

Unpatched Kaltura mwEmbed flaws enable file read and RCE

πŸ›‘οΈ CERT/CC disclosed two unpatched vulnerabilities in Kaltura's mwEmbed/html5lib player that allow unauthenticated remote file reads and remote code execution via unsafe PHP deserialization. The flaws (CVE-2026-19913 & CVE-2026-19912) stem from mwEmbedLoader.php accepting an attacker-controlled ServiceUrl and using PHP's unserialize() without validation. No patch is available and CERT/CC was unable to reach Kaltura; administrators are advised to restrict endpoint access, allow-list ServiceUrl, and take mitigation steps including rotating credentials in local.ini.
read more β†’

Critical Gitea file-read flaw patched in 1.27.1

πŸ”’ An unauthenticated attacker could read any file the Gitea service account can access in versions 1.22.1–1.27.0 by posting crafted Org-mode markup to the markup endpoint. The issue, tracked as CVE-2026-59774 and rated Critical (CVSS 9.8), was fixed in Gitea 1.27.1. Self-hosted admins should upgrade immediately and rotate exposed credentials if the endpoint was reached.
read more β†’

Rails fixes critical Active Storage flaw with RCE risk

πŸ›‘οΈ The Rails project patched a critical Active Storage vulnerability (CVE-2026-66066) that can let unauthenticated attackers read arbitrary files and potentially achieve remote code execution when libvips is used. The flaw affects multiple Rails branches before specified patch releases and requires accepting uploads from untrusted users. Administrators should upgrade libvips to 8.13+, apply Rails updates, and rotate exposed secrets. ImageMagick users are not affected by this vector.
read more β†’

Cursor flaw allows repo-root binaries to run

πŸ›‘οΈ Open a repository in Cursor on Windows and, if a file named git.exe is in the project root, Cursor runs it automatically without prompt. Whatever that binary does executes as the logged-in user and Cursor repeatedly spawns it while the project remains open. Mindgard reported the issue in December 2025, published full details seven months later, and no patch or Cursor advisory had been issued as of July 15, 2026.
read more β†’

Avada Builder Flaws Expose Files and Enable SQLi Risks

πŸ”’ The Avada Builder WordPress plugin contained two serious vulnerabilities impacting an estimated one million active installations. One flaw (CVE-2026-4782) allows authenticated users with subscriber access to read arbitrary server files via the plugin’s shortcode-rendering and the custom_svg parameter, exposing sensitive files like wp-config.php. The other issue (CVE-2026-4798) is a time-based blind SQL injection exploitable without authentication if WooCommerce was previously installed and then deactivated. Administrators are urged to update to Avada Builder 3.15.3 immediately.
read more β†’

Siemens Ruggedcom Rox Improper Access Control Flaw

⚠ The Siemens Ruggedcom Rox product contains an improper access control vulnerability in its web server JSON‑RPC interface that can allow an authenticated remote attacker to read arbitrary files on the underlying operating system with root privileges. Siemens has released updates and advises customers to upgrade to V2.17.1 or later. The issue is tracked as CWE-88 and CISA has republished the vendor advisory to increase visibility. Administrators should restrict network access and follow Siemens' operational security guidance.
read more β†’

Siemens ROS# Path Traversal Vulnerability β€” Update to 2.2.2

πŸ”’ A path traversal flaw exists in the ROS# file_server prior to 2.2.2, allowing attackers to read and write arbitrary files accessible to the account running the service. The issue arises from improper input sanitization and is tracked as CWE-23 with a CVSS v3 score of 9.1. Siemens released 2.2.2 as the vendor fix and recommends immediate updates. Temporary mitigations include running the service only on trusted networks and with restricted user rights.
read more β†’

Avada Builder Vulnerabilities Put One Million Sites at Risk

⚠️ Two newly disclosed flaws in the Avada Builder WordPress plugin place roughly one million sites at risk of arbitrary file read (CVE-2026-4782, CVSS 6.5) and unauthenticated time-based SQL injection (CVE-2026-4798, CVSS 7.5). The issues were reported to Wordfence in March and fixed in 3.15.2 and fully resolved in 3.15.3. Site owners are urged to update immediately and audit subscriber accounts and wp-config.php for signs of compromise.
read more β†’

File Read Flaw in Smart Slider 3 Hits 500K WordPress Sites

πŸ”’ A file-read vulnerability in Smart Slider 3 allows authenticated users with minimal privileges, including subscribers, to download arbitrary server files. The flaw (CVE-2026-3098) stems from missing capability checks and improper validation in the plugin's AJAX export actions, letting attackers export wp-config.php and other sensitive files. Researcher Dmitrii Ignatyev reported the issue and Wordfence validated the proof-of-concept. Nextendweb released a patch in version 3.5.1.34; site owners should update immediately.
read more β†’

Critical Flaws in Four Popular VS Code Extensions Reported

⚠️ OX Security researchers disclosed multiple high-severity vulnerabilities in four widely used VS Code extensions β€” Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview β€” collectively installed more than 125 million times. The flaws can enable local-file exfiltration, arbitrary JavaScript execution, and settings-based code execution; three remain unpatched while Microsoft fixed an XSS-style issue in Live Preview in version 0.4.16 (September 2025). Researchers advise disabling or uninstalling non-essential or untrusted extensions, avoiding untrusted configurations, keeping extensions updated, and hardening local networks and firewalls.
read more β†’

Critical VS Code Extension Flaws Expose 128M Installs

πŸ”’ OX Security disclosed critical and high-severity vulnerabilities in four widely used Visual Studio Code extensions with a combined 128 million downloads, exposing developers to file theft, remote code execution, and local network reconnaissance. Three CVEs were published; Microsoft privately patched Live Preview. The flaws also affected AI-powered IDEs Cursor and Windsurf, and OX Security said three maintainers did not respond to notifications. Researchers urge immediate updates, disabling unused extensions, and avoiding untrusted sites while localhost servers run.
read more β†’

Siemens NX CGM File Parsing Vulnerabilities β€” Update

⚠️ Siemens NX contains multiple file-parsing vulnerabilities in its handling of CGM files that can cause application crashes or enable arbitrary code execution when a malicious file is opened. Siemens has released fixes and advises updating to V2512 or later. Do not open untrusted CGM files and apply vendor updates promptly. Follow CISA guidance on network isolation and secure remote access.
read more β†’

Chainlit vulnerabilities allow file reads, SSRF in cloud

πŸ”’ Chainlit, a widely used open-source framework for building conversational AI, contained two high-severity flaws that enable arbitrary file reads and server-side request forgery without user interaction. Zafran Labs labeled the issues CVE-2026-22218 and CVE-2026-22219, which together can expose API keys, cloud credentials, source code, and internal services. The defects were fixed in v2.9.4; organizations should upgrade to 2.9.4 or later immediately and inspect for potential data exfiltration.
read more β†’

Chainlit Vulnerabilities Permit File Reads and SSRF Access

⚠️ Security researchers disclosed two critical vulnerabilities in the Python-based AI app framework Chainlit that allow unauthenticated attackers to read arbitrary server files and trigger SSRF requests. The flaws (CVE-2026-22218 and CVE-2026-22219), fixed in Chainlit 2.9.4, stem from an unvalidated custom Element type exposing path and URL properties. Exploits can leak environment variables, API keys, LLM prompts, and cloud credentials, enabling lateral movement and broader compromise.
read more β†’

Chainlit vulnerabilities expose files and enable SSRF

πŸ”’ Chainlit, a widely used framework for building conversational AI applications, contained two server-side vulnerabilities (CVE-2026-22218 and CVE-2026-22219) that allow authenticated users to read arbitrary files and trigger SSRF in affected deployments. The flaws stem from insufficient validation of user-controlled properties in custom elements and SQLAlchemy-backed storage. Combined, they can expose environment variables, cached prompts, API keys and cloud metadata, enabling lateral movement beyond the app layer. Chainlit released 2.9.4 on 24 December 2025 and users are advised to apply the patch immediately; temporary WAF signatures were published as mitigation.
read more β†’

Three MCP Git Server Flaws Enable File Access and RCE

⚠️ A trio of vulnerabilities in mcp-server-git, the official MCP Git server maintained by Anthropic, can be chained to read or delete arbitrary files and, in certain scenarios, achieve remote code execution. Cyata researcher Yarden Porat showed these issues are exploitable via prompt injection when an AI assistant ingests attacker-controlled content such as a malicious README or poisoned issue text. Fixes were released in 2025.9.25 and 2025.12.18; users should update the Python package promptly to mitigate risk.
read more β†’

Siemens SINEC Security Monitor: Update Recommended

πŸ”’ Siemens has released a security update for SINEC Security Monitor addressing two vulnerabilities (CVE-2025-40830, CVE-2025-40831) in versions before V4.10.0. The flaws allow an authenticated user to read or write arbitrary files via the ssmctl-client file_transfer feature and to cause a report-generation denial-of-service. Siemens recommends updating to V4.10.0 or later and reducing network exposure per operational guidance.
read more β†’