CVE-2026-19827

Summary

A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.java of the component logDetailCat Endpoint. This manipulation of the argument executorAddress causes path traversal. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project closed the issue report as "not planned" without any further explanation.

Affected Software

VendorProductVersion RangeStatus
alldatacenteralldata0.6.0affected
alldatacenteralldata0.6.1affected
alldatacenteralldata0.6.2affected
alldatacenteralldata0.6.3affected
alldatacenteralldata0.6.4affected
alldatacenteralldata0.6.5affected
alldatacenteralldata0.6.6affected
alldatacenteralldata0.6.7affected
alldatacenteralldata0.6.8affected

Weaknesses

  • CWE-22: Path Traversal

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

References