Back

MEDIUM

ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability

Published Jun 24, 2026

Description

ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authentication is required to exploit this vulnerability.

The specific flaw exists within the updateLicense method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files or create a denial-of-service condition on the system. Was ZDI-CAN-28502.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner zdi
Published Jun 24, 2026
Updated Jun 25, 2026
Reserved May 27, 2026

CISA Vulnrichment

Updated Jun 25, 2026

NVD

Status Analyzed
Modified Jun 27, 2026

Red Hat

No data

ENISA EUVD

Assigner zdi
Published Jun 24, 2026
Updated Jun 25, 2026

GitHub

No data