SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-78602

MEDIUM · CVSS 5.3 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Elastic Maps Server is vulnerable to a path traversal issue, allowing unauthenticated attackers to access and disclose sensitive files outside the designated content directory. This could lead to unauthorized information exposure, potentially compromising sensitive data. Organizations using Elastic Maps Server should prioritize addressing this vulnerability to mitigate the risk of data leakage.

CVE
CVE-2026-78602
Severity
MEDIUM
CVSS
5.3
EPSS
0.38%

Original NVD Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the contents of files outside its intended content directory that are readable by the server process.

Related CVEs

Other vulnerabilities affecting the same vendor(s)