Description
Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.
Published: 2026-07-14
Score: 7.7 High
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Ivanti Xtraction is a path traversal flaw, classified as CWE‑23, that lets a remote authenticated attacker read files located outside the web root that the web application process can access. By manipulating the path component of HTTP requests, the attacker can bypass directory restrictions and obtain unauthorized disclosure. The description does not specify which files can be accessed, so the exact scope of disclosure is not explicitly defined.

Affected Systems

Ivanti Xtraction products older than version 2026.2.1 are affected. Systems running 2026.2.0 or earlier are exposed to the path traversal risk.

Risk and Exploitability

The flaw carries a CVSS score of 7.7, classifying it as high severity, and the EPSS score of 1% indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote authenticated access; a legitimate user must have a valid login. After authentication, the attacker can navigate above the web root and read any file accessible to the application’s file system process. The description does not explicitly state whether files outside the web root include system or user data, so that potential scope is not confirmed.

Generated by OpenCVE AI on July 31, 2026 at 10:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch to update Ivanti Xtraction to version 2026.2.1 or later.
  • Restrict authentication to trusted accounts and enforce network segmentation to limit remote access to the Xtraction installation.
  • Monitor application logs for suspicious file read requests and configure alerts for path traversal patterns to detect potential exploitation attempts.

Generated by OpenCVE AI on July 31, 2026 at 10:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Enables Remote Authenticated File Disclosure in Ivanti Xtraction

Wed, 29 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ivanti Xtraction Enables Remote Authenticated Arbitrary File Disclosure

Fri, 24 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ivanti Xtraction Enables Remote Authenticated Arbitrary File Disclosure

Mon, 20 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ivanti Xtraction Allows Remote Authenticated File Access

Thu, 16 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Path Traversal in Ivanti Xtraction Allows Remote Authenticated File Access

Thu, 16 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ivanti
Ivanti xtraction
Vendors & Products Ivanti
Ivanti xtraction

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Ivanti Xtraction
cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-07-14T14:45:41.619Z

Reserved: 2026-07-06T21:20:45.037Z

Link: CVE-2026-14903

cve-icon Vulnrichment

Updated: 2026-07-14T14:45:08.422Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:30:17Z

Weaknesses
  • CWE-23

    Relative Path Traversal