CVE-2026-8043 PUBLISHED

Assigner: ivanti
Reserved: 06.05.2026 Published: 12.05.2026 Updated: 12.05.2026

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVSS Score: 9.6

Product Status

Vendor ivanti
Product Xtraction
Versions Default: affected
  • Version 2026.2 is unaffected

References

Problem Types

  • CWE-73 External control of file name or path CWE

Impacts

  • CAPEC-165 File Manipulation