Path Traversal Vulnerability in AKINSOFT Wolvox9 ERP
A path traversal vulnerability (CVE-2026-15585) in AKINSOFT Wolvox9 ERP KontrolPanel.exe versions s26.02.17 through s26.02.21 allows unauthenticated remote attackers to read arbitrary files from the host filesystem.
CVE search metadata
CVE search record: CVE-2026-15585. Severity: high. CVSS: 7.5. KEV: no. Product: AKINSOFT Wolvox9 ERP. Brief: Path Traversal Vulnerability in AKINSOFT Wolvox9 ERP. Brief link: https://feed.craftedsignal.io/briefs/2026-08-akinsoft-path-traversal/
AKINSOFT Wolvox9 ERP contains a path traversal vulnerability (CVE-2026-15585) within the KontrolPanel.exe component. The vulnerability arises from an improper limitation of a pathname to a restricted directory, enabling unauthenticated remote attackers to manipulate file paths to access files outside the intended web root. This flaw affects product versions starting from s26.02.17 up to, but not including, s26.02.22. Successful exploitation results in unauthorized disclosure of sensitive files residing on the host operating system. As this is an unauthenticated vector, it presents a significant risk to organizations hosting this software on internet-facing infrastructure.
Impact
The vulnerability allows an unauthenticated, remote attacker to bypass directory restrictions and access arbitrary files on the underlying Windows system. This can lead to the exposure of sensitive configuration files, credentials, or application data. Given the CVSS 3.1 base score of 7.5, the impact is considered high, particularly for organizations that have not updated to version 26.02.22 or later.
Recommendation
- Update AKINSOFT Wolvox9 ERP / KontrolPanel.exe to version 26.02.22 or higher immediately to remediate the path traversal vulnerability.
- Restrict access to the KontrolPanel.exe interface via network-level controls if an immediate update is not possible.
- Review web server access logs for requests containing directory traversal sequences (e.g., ../ or ..%2f) directed at the application to identify potential exploitation attempts.
Immediate actions
Patch AKINSOFT Wolvox9 ERP to version 26.02.22