Path traversal in Suricata - CVE-2026-45767
Published: June 3, 2026
Suricata
Detailed vulnerability description
The vulnerability allows a remote user to overwrite arbitrary files.
The vulnerability exists due to path traversal in the datasets save and load command handling when loading or reloading a malicious rule that combines save to an absolute filename with the load command. A remote privileged user can provide a specially crafted rule to overwrite arbitrary files.