External Control of File Name or Path in Endpoint Manager - CVE-2026-18127

 

External Control of File Name or Path in Endpoint Manager - CVE-2026-18127

Published: August 11, 2026


Vulnerability identifier: #VU141422
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-18127
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to overwrite data in an S3 bucket configured for session recording storage.

The vulnerability exists due to external control of a filename in the core when handling session recording storage filenames. A remote user can control a filename to gain full write control over an S3 bucket configured for session recording storage to overwrite data in an S3 bucket configured for session recording storage.

The issue affects configurations that use an S3 bucket for session recording storage.


Affected software

Endpoint Manager

How to mitigate CVE-2026-18127

Install security update from vendor's website.

Endpoint Manager - update to 2024 SU7

External References

Related Security Bulletins