Description
A validation vulnerability has been identified in certain web features related to file management or upload in several products of the TAO 2.0 suite. This vulnerability could allow an attacker capable of interacting with the affected feature to attempt to access file system resources outside the scope intended by the application.
Published: 2026-07-06
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A validation flaw in the TAO 2.0 suite web features that handle file management or uploads allows an attacker who can reach the affected endpoint to attempt path traversal and read or write files outside the intended directory. This grants unauthorized access to sensitive files and could compromise confidentiality, integrity, or availability of data and the overall system.

Affected Systems

Customers using T-Systems Archivo, Buroweb, MyTAO or eStima are impacted. The vulnerability exists in any release prior to version 2602.0.0; instances of the four products running older versions must be identified and upgraded.

Risk and Exploitability

The CVSS score of 6 reflects moderate severity, and the EPSS score of < 1% indicates a very low exploitation probability. The flaw appears to be triggered through web features; based on the description, the likely attack vector is remote via the internet. An attacker who can invoke the vulnerable file‑handling endpoint—whether through a public URL or an authenticated session—may navigate the server filesystem arbitrarily, potentially exposing or damaging critical data. The vulnerability is not listed in CISA KEV, indicating no known mass exploitation at the time of reporting.

Generated by OpenCVE AI on July 26, 2026 at 20:33 UTC.

Remediation

Vendor Solution

The vulnerability, reported by the T-Systems team itself, has been fixed in version 2602.0.0 of the affected products. The general recommendation is to update to that version or any later version that includes these fixes.


OpenCVE Recommended Actions

  • Upgrade all affected T-Systems products to version 2602.0.0 or later, which contains the fix.
  • If an immediate upgrade is not possible, limit exposure by disabling or restricting access to the file-upload and file-management features, or block the affected web endpoints from external networks.
  • Apply secure path validation logic on the server side to ensure that any user-supplied paths remain confined within the intended directories, as an interim defensive measure.

Generated by OpenCVE AI on July 26, 2026 at 20:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description A validation vulnerability has been identified in certain web features related to file management or upload in several products of the TAO 2.0 suite. This vulnerability could allow an attacker capable of interacting with the affected feature to attempt to access file system resources outside the scope intended by the application.
Title Unauthorized access to files in T-Systems products
First Time appeared T-systems
T-systems archivo
T-systems buroweb
T-systems estima
T-systems mytao
Weaknesses CWE-22
CPEs cpe:2.3:a:t-systems:archivo:*:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:archivo:2602.00:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:buroweb:*:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:buroweb:2602.00:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:estima:*:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:estima:2602.00:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:mytao:*:*:*:*:*:*:*:*
cpe:2.3:a:t-systems:mytao:2602.00:*:*:*:*:*:*:*
Vendors & Products T-systems
T-systems archivo
T-systems buroweb
T-systems estima
T-systems mytao
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-07-06T16:12:10.409Z

Reserved: 2026-04-27T11:08:09.070Z

Link: CVE-2026-7185

cve-icon Vulnrichment

Updated: 2026-07-06T16:12:06.398Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:45:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')