CVE-2026-29205
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Exploitability: 3.9 / Impact: 4.7
Source: support@hackerone.com (Secondary)
Description
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
References (1)
Timeline
No history available yet.