CRITICAL
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks
Published May 12, 2026
9.6
CRITICALCVSS 3.1
EPSS 1.15%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.