{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/akin-software-computer-import-export-industry-and-trade-ltd./feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-15585"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AKINSOFT Wolvox9 ERP"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","erp"],"_cs_type":"advisory","_cs_vendors":["AKIN Software Computer Import Export Industry and Trade Ltd."],"content_html":"\u003cp\u003eAKINSOFT Wolvox9 ERP contains a path traversal vulnerability (CVE-2026-15585) within the KontrolPanel.exe component. The vulnerability arises from an improper limitation of a pathname to a restricted directory, enabling unauthenticated remote attackers to manipulate file paths to access files outside the intended web root. This flaw affects product versions starting from s26.02.17 up to, but not including, s26.02.22. Successful exploitation results in unauthorized disclosure of sensitive files residing on the host operating system. As this is an unauthenticated vector, it presents a significant risk to organizations hosting this software on internet-facing infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows an unauthenticated, remote attacker to bypass directory restrictions and access arbitrary files on the underlying Windows system. This can lead to the exposure of sensitive configuration files, credentials, or application data. Given the CVSS 3.1 base score of 7.5, the impact is considered high, particularly for organizations that have not updated to version 26.02.22 or later.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate AKINSOFT Wolvox9 ERP / KontrolPanel.exe to version 26.02.22 or higher immediately to remediate the path traversal vulnerability.\u003c/li\u003e\n\u003cli\u003eRestrict access to the KontrolPanel.exe interface via network-level controls if an immediate update is not possible.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for requests containing directory traversal sequences (e.g., ../ or ..%2f) directed at the application to identify potential exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T12:52:20Z","date_published":"2026-08-18T12:52:20Z","id":"https://feed.craftedsignal.io/briefs/2026-08-akinsoft-path-traversal/","summary":"A path traversal vulnerability (CVE-2026-15585) in AKINSOFT Wolvox9 ERP KontrolPanel.exe versions s26.02.17 through s26.02.21 allows unauthenticated remote attackers to read arbitrary files from the host filesystem.","title":"Path Traversal Vulnerability in AKINSOFT Wolvox9 ERP","url":"https://feed.craftedsignal.io/briefs/2026-08-akinsoft-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - AKIN Software Computer Import Export Industry and Trade Ltd.","version":"https://jsonfeed.org/version/1.1"}