#VU125046 Path traversal in emissary - CVE-2026-35583
Published: April 7, 2026
emissary
National Security Agency
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in the configuration API endpoint /api/configuration/{name} when processing crafted configuration names. A remote attacker can send a specially crafted request to disclose sensitive information.
The issue can be triggered by using URL-encoded variants, double-encoded sequences, or Unicode normalization to access configuration files outside the intended directory.