{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cloud-commander--19.20.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cloud_commander:cloud_commander:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-82460"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cloud Commander (\u003c 19.20.2)"],"_cs_severities":["critical"],"_cs_tags":["directory-traversal","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Cloud Commander"],"content_html":"\u003cp\u003eCloud Commander versions prior to 19.20.2 contain a directory traversal vulnerability within the REST file-operation and markdown endpoints. The flaw exists due to insufficient validation of path normalization, allowing an unauthenticated attacker to supply crafted path traversal sequences. By exploiting this, an attacker can perform unauthorized file system operations, including reading sensitive configuration files, modifying existing files, or writing new files to locations outside of the configured root directory. This vulnerability presents a high risk for full server compromise depending on the permissions of the user account running the Cloud Commander service.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain unauthorized access to the filesystem. This can lead to the exfiltration of sensitive data, the injection of malicious code into system files, or the deletion of critical resources, potentially resulting in full system compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate all instances of Cloud Commander to version 19.20.2 or later immediately to mitigate the underlying path normalization flaw.\u003c/p\u003e\n","date_modified":"2026-08-29T17:40:36Z","date_published":"2026-08-29T17:40:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cloud-commander-traversal/","summary":"Cloud Commander versions prior to 19.20.2 are vulnerable to a directory traversal flaw in REST file-operation and markdown endpoints, allowing unauthenticated attackers to read or write arbitrary files.","title":"Directory Traversal Vulnerability in Cloud Commander","url":"https://feed.craftedsignal.io/briefs/2026-08-cloud-commander-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cloud Commander (\u003c 19.20.2)","version":"https://jsonfeed.org/version/1.1"}