CyberRota Analysis
AI-GeneratedIvanti Xtraction versions prior to 2026.2.1 are vulnerable to a path traversal flaw that enables remote authenticated attackers to access and read arbitrary files outside the web root. This vulnerability poses a significant risk of data exposure, making it critical for organizations using affected versions to prioritize immediate patching. Users of Ivanti Xtraction should assess their systems and implement the necessary updates to mitigate potential data breaches.
CVE
CVE-2026-14903
Severity
HIGH
CVSS
7.7
EPSS
1.04%
Ivanti
Original NVD Description
Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.
Related CVEs
Other vulnerabilities affecting the same vendor(s)