Description
A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with administrative credentials for the web interface could submit an archive name containing traversal sequences and delete arbitrary files reachable by the Arc process, which runs with administrative privileges on the host.
Published: 2026-08-11
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a path traversal bug in the offline archives component of the Arc local web interface; it allows a user who has local administrative rights to provide an archive name containing traversal sequences that cause the Arc process, which runs with elevated host privileges, to delete arbitrary files within its file system. This can erase critical configuration, backup, or operational files and disrupt device functionality.

Affected Systems

All Nozomi Networks Arc deployments running any version earlier than 2.7.0 that expose the local web interface are affected. The vulnerability resides in the offline archives feature and requires local access to the web interface.

Risk and Exploitability

The CVSS score of 6.8 places the flaw in the medium severity range. Because the attack requires local administrative access to the web interface and no publicly documented exploitation exists (EPSS is not available and it is not listed in the CISA KEV catalog), the likelihood of exploitation is limited to environments where an attacker can gain local admin credentials. If such credentials are in use, the attacker can delete any file reachable by the Arc process, potentially compromising device operation or data integrity.

Generated by OpenCVE AI on August 11, 2026 at 12:20 UTC.

Remediation

Vendor Solution

Upgrade Arc to v2.7.0 or later.


Vendor Workaround

Review the credentials of the web interface and rotate them by relaunching Arc's local web server if they may have been exposed to untrusted users.


OpenCVE Recommended Actions

  • Upgrade Arc to version 2.7.0 or later to eliminate the path traversal flaw.
  • If an upgrade cannot be performed immediately, rotate the credentials used for the local web interface and restart the Arc local web server to reduce the risk of credential exposure; ensure only trusted personnel have access.
  • Restrict or disable the local web interface for devices that do not require it, limiting surface area to trusted networks only.

Generated by OpenCVE AI on August 11, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with administrative credentials for the web interface could submit an archive name containing traversal sequences and delete arbitrary files reachable by the Arc process, which runs with administrative privileges on the host.
Title Path traversal in the Offline archives functionality of the local web interface in Arc before v2.7.0
First Time appeared Nozomi Networks
Nozomi Networks arc
Weaknesses CWE-22
CPEs cpe:2.3:a:nozomi_networks:arc:*:*:*:*:*:*:*:*
Vendors & Products Nozomi Networks
Nozomi Networks arc
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Nozomi Networks Arc
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-08-11T14:14:16.712Z

Reserved: 2026-03-24T16:06:11.950Z

Link: CVE-2026-33922

cve-icon Vulnrichment

Updated: 2026-08-11T14:14:09.444Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T10:17:12.257

Modified: 2026-08-28T19:46:29.323

Link: CVE-2026-33922

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-11T09:48:35Z

Links: CVE-2026-33922 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T12:30:09Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')