Description
An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request.
Published: 2026-06-05
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a directory traversal flaw in the cluster-admin:backup-datastore component of the OpenDaylight Controller version 12.0.5. It allows an attacker to craft a request that causes the component to resolve file paths outside the intended backup directory. The input does not specify the precise consequence of the traversal, so the impact is limited to the potential for unauthorized file access or modifying configuration files, as defined by CWE‑22.

Affected Systems

The flaw is present in OpenDaylight Controller 12.0.5. No other affected versions are mentioned in the input.

Risk and Exploitability

CVSS and EPSS scores are not provided, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote API request to the backup datastore endpoint; based on the description, it is inferred that no authentication requirement is explicitly stated, meaning the exploit could target both authenticated and unauthenticated requests depending on deployment configuration.

Generated by OpenCVE AI on June 5, 2026 at 21:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the OpenDaylight project for an official patch or upgrade that addresses the directory traversal flaw in the cluster-admin:backup-datastore component.
  • Implement strict input validation for backup datastore requests, ensuring that any file path supplied is resolved relative to a fixed backup directory and does not allow traversal beyond that directory, following CWE‑22 best‑practice guidelines.
  • Restrict external access to the backup datastore API endpoint to trusted administrators by enforcing authentication and role‑based access controls to limit the potential for exploitation.

Generated by OpenCVE AI on June 5, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Title OpenDaylight Controller Directory Traversal via Backup Datastore
Weaknesses CWE-22

Fri, 05 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Description An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-05T16:59:27.377Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36500

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-06-05T18:17:16.777

Modified: 2026-06-05T19:02:13.790

Link: CVE-2026-36500

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T21:15:05Z

Weaknesses