External Control of File Name or Path in Xtraction - CVE-2026-8043
Published: May 12, 2026
Xtraction
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information and conduct client-side attacks.
The vulnerability exists due to external control of a file name in Ivanti Xtraction when handling file names for file access and web directory writes. A remote user can supply a crafted file name to read sensitive files and write arbitrary HTML files to a web directory to disclose sensitive information and conduct client-side attacks.