Path traversal in Gaia - CVE-2026-48133
Published: May 28, 2026
Gaia
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in the Identity Awareness captive portal when handling browser-based authentication requests. A remote attacker can send a crafted request to disclose sensitive information.
Only systems with the Identity Awareness blade enabled with Browser-Based Authentication are vulnerable.