Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS allows Path Traversal.

This issue affects Liman MYS: from 2.3.2 before 2.3.4-1124.
Published: 2026-09-24
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Path Traversal
Action: Patch
AI Analysis

Impact

Improper limitation of a pathname to a restricted directory allows an attacker to traverse directory boundaries and read or modify files outside the intended scope. This flaw can expose configuration files, sensitive data, or allow further exploitation, compromising confidentiality and integrity. It is classified as CWE‑22, a common path‑traversal weakness.

Affected Systems

The affected product is HAVELSAN Inc.'s Liman MYS. Vulnerable versions are 2.3.2 through the release prior to 2.3.4‑1124. Systems must be upgraded to version 2.3.4‑1124 or later to eliminate the issue.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, implying limited known exploitation. Based on the disclosure, the flaw is likely exploitable via the application interface when an attacker can supply a crafted filepath; authentication requirements are not specified, so the attack vector is inferred and may require internal or network access to the affected system.

Generated by OpenCVE AI on September 24, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade to Liman MYS version 2.3.4‑1124 or later.
  • Restrict the application’s file input handling by validating and sanitizing paths against a whitelist of allowed directories.
  • Enforce network segmentation and limit external exposure of the system to reduce the attack surface.
  • Monitor logs for anomalous file access patterns and raise alerts on suspicious traversal attempts.

Generated by OpenCVE AI on September 24, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Havelsan
Havelsan liman Mys
Vendors & Products Havelsan
Havelsan liman Mys

Thu, 24 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS allows Path Traversal. This issue affects Liman MYS: from 2.3.2 before 2.3.4-1124.
Title Path Traversal in HAVELSAN's Liman MYS
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Havelsan Liman Mys
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-24T12:19:54.977Z

Reserved: 2026-08-11T08:45:38.496Z

Link: CVE-2026-19532

cve-icon Vulnrichment

Updated: 2026-09-24T12:19:50.770Z

cve-icon NVD

Status : Received

Published: 2026-09-24T12:17:12.030

Modified: 2026-09-24T13:17:09.637

Link: CVE-2026-19532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T13:30:18Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')