CVE-2026-19827

medium

Description

A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.java of the component logDetailCat Endpoint. This manipulation of the argument executorAddress causes path traversal. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project closed the issue report as "not planned" without any further explanation.

References

https://vuldb.com/vuln/389960/cti

https://vuldb.com/vuln/389960

https://vuldb.com/submit/870238

https://vuldb.com/cve/CVE-2026-19827

https://github.com/alldatacenter/alldata/issues/834

https://github.com/alldatacenter/alldata/

Details

Source: Mitre, NVD

Published: 2026-08-14

Updated: 2026-08-14

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium

CVSS v4

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Severity: Medium