CVE-2026-5966 PUBLISHED

TeamT5|ThreatSonar Anti-Ransomware - Arbitrary File Deletion

Assigner: twcert
Reserved: 09.04.2026 Published: 20.04.2026 Updated: 20.04.2026

ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.2

Product Status

Vendor TeamT5
Product ThreatSonar Anti-Ransomware
Versions Default: unaffected
  • affected from 0 to 4.0.0 (incl.)

Solutions

Please install hotpatch version 20260302.

References

Problem Types

  • CWE-23 Relative path traversal CWE

Impacts

  • CAPEC-139 Relative Path Traversal