Impact
The vulnerability in Ivanti Xtraction is a path traversal flaw, classified as CWE‑23, that lets a remote authenticated attacker read files located outside the web root that the web application process can access. By manipulating the path component of HTTP requests, the attacker can bypass directory restrictions and obtain unauthorized disclosure. The description does not specify which files can be accessed, so the exact scope of disclosure is not explicitly defined.
Affected Systems
Ivanti Xtraction products older than version 2026.2.1 are affected. Systems running 2026.2.0 or earlier are exposed to the path traversal risk.
Risk and Exploitability
The flaw carries a CVSS score of 7.7, classifying it as high severity, and the EPSS score of 1% indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote authenticated access; a legitimate user must have a valid login. After authentication, the attacker can navigate above the web root and read any file accessible to the application’s file system process. The description does not explicitly state whether files outside the web root include system or user data, so that potential scope is not confirmed.
OpenCVE Enrichment