Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal.

This issue affects AKINSOFT Wolvox9 ERP / KontrolPanel.exe: from s26.02.17 before 26.02.22.
Published: 2026-08-18
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper limitation of a pathname to a restricted directory in the KontrolPanel.exe component of AKINSOFT Wolvox9 ERP allows a path traversal attack. An attacker could supply file paths containing directory separators and navigate outside the intended directory scope, potentially accessing sensitive configuration files, credentials, or system files. This weakness corresponds to CWE-22 and can lead to confidentiality breaches or unauthorized file modification. The vulnerability impacts the local system where the application is installed and does not immediately provide remote code execution capabilities but can be leveraged to gather critical data.

Affected Systems

AKINSOFT Wolvox9 ERP, specifically the KontrolPanel.exe component, from version s26.02.17 up through, but not including, s26.02.22. The affected product is released by AKIN Software Computer Import Export Industry and Trade Ltd.

Risk and Exploitability

The CVSS score of 7.5 indicates moderate‑to‑high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited observed exploitation. Likely attack vectors include attempts at manipulating the file selection UI or API parameters to supply crafted path inputs. Attackers with local or application‑level access could exploit this weakness to read restricted files, which could lead to further compromise if sensitive data is exposed.

Generated by OpenCVE AI on August 18, 2026 at 12:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade AKINSOFT Wolvox9 ERP to version 26.02.22 or later, which removes the path traversal flaw
  • Implement input validation on file paths to reject or sanitize any relative path components before passing them to the file system
  • Add file‑level access controls and restrict the KontrolPanel.exe working directory so that even if traversal is attempted, only permitted files can be accessed
  • If immediate upgrade is not possible, isolate the application in a sandboxed environment and monitor for unusual file access attempts

Generated by OpenCVE AI on August 18, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal. This issue affects AKINSOFT Wolvox9 ERP / KontrolPanel.exe: from s26.02.17 before 26.02.22.
Title Path Traversal in AKIN Software's Wolvox9 ERP
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-18T11:23:26.689Z

Reserved: 2026-07-13T11:57:08.756Z

Link: CVE-2026-15585

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T12:17:23.110

Modified: 2026-08-18T12:17:23.110

Link: CVE-2026-15585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T12:30:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')