Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory.
History

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Coderaiser
Coderaiser cloudcmd
Vendors & Products Coderaiser
Coderaiser cloudcmd

Sat, 29 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory.
Title Cloud Commander before 19.20.2 Directory Traversal via REST and Markdown
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-08-29T16:35:24.787Z

Updated: 2026-08-31T18:35:13.815Z

Reserved: 2026-08-29T14:10:59.924Z

Link: CVE-2026-82460

cve-icon Vulnrichment

Updated: 2026-08-31T18:34:47.423Z

cve-icon NVD

Status : Received

Published: 2026-08-29T17:17:58.060

Modified: 2026-08-31T19:17:20.013

Link: CVE-2026-82460

cve-icon Redhat

No data.