Improper Handling of Windows Device Names in Werkzeug - CVE-2026-21860

 

Improper Handling of Windows Device Names in Werkzeug - CVE-2026-21860

Published: March 5, 2026


Vulnerability identifier: #VU123583
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-21860
CWE-ID: CWE-67
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. Windows still accepts them with any file extension, such as CON.txt, or trailing spaces such as CON. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.



Affected software

Werkzeug
IBM Cloud Pak for Data System
IBM Maximo Application Suite
watsonx Code Assistant On Prem
Maximo Application Suite - Predict Component
Maximo Application Suite - Location Service for Esri Component
Maximo Application Suite Ai Service
Storage Protect Plus Server
Robotic Process Automation for Cloud Pak

How to mitigate CVE-2026-21860

Install updates from vendor's website.

Werkzeug - update to 3.1.5
IBM Cloud Pak for Data System - update to 1.0.10.0
watsonx Code Assistant On Prem - update to 5.3.1
Maximo Application Suite - Predict Component - addressed in versions 8.8.14, 8.9.16, 9.0.13, 9.1.6
IBM Maximo Application Suite - addressed in versions 8.10.36, 8.11.33, 9.0.22, 9.1.11
Maximo Application Suite - Location Service for Esri Component - addressed in versions 9.0.7, 9.1.6
Maximo Application Suite Ai Service - update to 9.1.13
Storage Protect Plus Server - update to 10.1.18
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.2

External References

Related Security Bulletins