Description
A validation vulnerability has been identified in certain web features related to file management or upload in several products of the TAO 2.0 suite. This vulnerability could allow an attacker capable of interacting with the affected feature to attempt to access file system resources outside the scope intended by the application.
Published: 2026-07-06
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A validation flaw in the TAO 2.0 suite web features that oversee file management or uploads permits an attacker who can interact with the vulnerable endpoint to attempt path traversal, enabling access to files or directories outside the intended application scope. This can lead to reading or modifying sensitive data, compromising confidentiality, integrity, or system availability.

Affected Systems

Customers running T-Systems Archivo, Buroweb, MyTAO, or eStima in any release prior to version 2602.0.0 are vulnerable. Identifying assets running older versions and planning upgrades is essential.

Risk and Exploitability

The CVSS score of 6 indicates moderate severity while the EPSS score of < 1% suggests a very low exploitation probability. The vulnerability is not listed in CISA KEV, implying no known mass exploitation. The flaw is likely triggered through web-based file handling endpoints; remote attackers who reach these endpoints could navigate the server file system arbitrarily to read or write files beyond the intended directory.

Generated by OpenCVE AI on August 1, 2026 at 18:35 UTC.

Remediation

Vendor Solution

The vulnerability, reported by the T-Systems team itself, has been fixed in version 2602.0.0 of the affected products. The general recommendation is to update to that version or any later version that includes these fixes.


OpenCVE Recommended Actions

  • Upgrade all affected T-Systems products to version 2602.0.0 or later, which incorporates the fix.
  • If an immediate upgrade cannot be performed, limit exposure by disabling or restricting access to the file‑upload and file‑management features, or block the affected web endpoints from external networks.
  • Implement secure server‑side path‑validation logic to ensure that any user-supplied paths remain confined within the intended directories, serving as an interim defensive measure.

Generated by OpenCVE AI on August 1, 2026 at 18:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description A validation vulnerability has been identified in certain web features related to file management or upload in several products of the TAO 2.0 suite. This vulnerability could allow an attacker capable of interacting with the affected feature to attempt to access file system resources outside the scope intended by the application.
Title Unauthorized access to files in T-Systems products
First Time appeared T-systems
T-systems archivo
T-systems buroweb
T-systems estima
T-systems mytao
Weaknesses CWE-22
CPEs cpe:2.3:a:t-systems:archivo:*:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:archivo:2602.00:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:buroweb:*:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:buroweb:2602.00:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:estima:*:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:estima:2602.00:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:mytao:*:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:mytao:2602.00:*:*:*:*:*:*:*
Vendors & Products T-systems
T-systems archivo
T-systems buroweb
T-systems estima
T-systems mytao
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-07-06T16:12:10.409Z

Reserved: 2026-04-27T11:08:09.070Z

Link: CVE-2026-7185

cve-icon Vulnrichment

Updated: 2026-07-06T16:12:06.398Z

cve-icon NVD

Status : Deferred

Published: 2026-07-06T15:16:41.080

Modified: 2026-07-06T18:41:46.210

Link: CVE-2026-7185

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T18:45:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')