Directory Traversal Vulnerability in Cloud Commander
Cloud Commander versions prior to 19.20.2 are vulnerable to a directory traversal flaw in REST file-operation and markdown endpoints, allowing unauthenticated attackers to read or write arbitrary files.
CVE search metadata
CVE search record: CVE-2026-82460. Severity: critical. CVSS: 9.8. KEV: no. Product: Cloud Commander (< 19.20.2). Brief: Directory Traversal Vulnerability in Cloud Commander. Brief link: https://feed.craftedsignal.io/briefs/2026-08-cloud-commander-traversal/
Cloud Commander versions prior to 19.20.2 contain a directory traversal vulnerability within the REST file-operation and markdown endpoints. The flaw exists due to insufficient validation of path normalization, allowing an unauthenticated attacker to supply crafted path traversal sequences. By exploiting this, an attacker can perform unauthorized file system operations, including reading sensitive configuration files, modifying existing files, or writing new files to locations outside of the configured root directory. This vulnerability presents a high risk for full server compromise depending on the permissions of the user account running the Cloud Commander service.
Impact
Successful exploitation allows unauthenticated remote attackers to gain unauthorized access to the filesystem. This can lead to the exfiltration of sensitive data, the injection of malicious code into system files, or the deletion of critical resources, potentially resulting in full system compromise.
Recommendation
Update all instances of Cloud Commander to version 19.20.2 or later immediately to mitigate the underlying path normalization flaw.
Mitigations
Upgrade Cloud Commander to version 19.20.2 or later
CVE-2026-82460