Description
A vulnerability was found in CoCoTeaNet CyreneAdmin up to 1.3.0. This affects an unknown part of the file /api/system/user/getAvatar of the component Image Handler. Performing a manipulation of the argument Avatar results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used.
Published: 2026-02-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Path Traversal
Action: Apply patch
AI Analysis

Impact

A flaw in the Image Handler of CoCoTeaNet CyreneAdmin allows an attacker to craft a special Avatar parameter to walk out of the designated file directory and read arbitrary files on the host. This path traversal weakness can expose sensitive configuration files, credentials, or other confidential data and therefore threatens confidentiality. The vulnerability corresponds to CWE‑22.

Affected Systems

The affected product is CoCoTeaNet CyreneAdmin, with all releases up to and including 1.3.0 vulnerable. The flaw resides in the /api/system/user/getAvatar endpoint and is present regardless of product component configuration. Any installation exposing this API is at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity. The EPSS score of less than 1 % suggests a low likelihood of exploitation at present, though a publicly disclosed exploit demonstrates the practical ability to read files. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring only an HTTP request to the vulnerable endpoint. The potential impact of accessing arbitrary files makes this issue a serious concern for publicly exposed instances.

Generated by OpenCVE AI on April 18, 2026 at 11:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CoCoTeaNet CyreneAdmin to a version newer than 1.3.0 that fixes the path‑traversal bug.
  • Add server‑side validation on the Avatar query parameter to reject sequences that contain directory traversal characters or to restrict the value to a safe whitelist of filenames.
  • Configure the web application firewall or the web server to detect and block directory‑traversal patterns in requests to the /api/system/user/getAvatar endpoint.

Generated by OpenCVE AI on April 18, 2026 at 11:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 24 Feb 2026 02:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Feb 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:cocoteanet:cyreneadmin:*:*:*:*:*:*:*:*

Thu, 19 Feb 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Cocoteanet
Cocoteanet cyreneadmin
Vendors & Products Cocoteanet
Cocoteanet cyreneadmin

Thu, 19 Feb 2026 02:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in CoCoTeaNet CyreneAdmin up to 1.3.0. This affects an unknown part of the file /api/system/user/getAvatar of the component Image Handler. Performing a manipulation of the argument Avatar results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used.
Title CoCoTeaNet CyreneAdmin Image getAvatar path traversal
Weaknesses CWE-22
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Cocoteanet Cyreneadmin
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-24T01:45:15.649Z

Reserved: 2026-02-18T14:20:35.082Z

Link: CVE-2026-2692

cve-icon Vulnrichment

Updated: 2026-02-24T01:45:12.404Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-19T07:17:48.470

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-2692

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T12:00:05Z

Weaknesses