Description
Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary files accessible to the testfs backend process.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized file reading (information disclosure)
Action: Patch immediately
AI Analysis

Impact

The vulnerability resides in the /tags/{tag} endpoint of Uber Kraken, which does not validate the tag parameter. By supplying percent‑encoded parent‑directory segments, an attacker can escape the configured storage root and read arbitrary files that the testfs backend process can access. This enables the disclosure of sensitive data, including configuration files or credentials, thereby compromising confidentiality.

Affected Systems

Uber Kraken products prior to version 0.1.30 are affected. The issue exists in all releases up to and including 0.1.29 of the Uber Kraken project.

Risk and Exploitability

With a CVSS score of 8.7 the vulnerability is considered high severity. The EPSS score of less than 1% indicates that exploitation is unlikely but not impossible, and the vulnerability is not listed in the CISA KEV catalog. Attackers do not need authentication and can trigger the vulnerability by sending arbitrary requests to the public /tags endpoint. The primary impact is the unauthorized reading of files, which threatens confidentiality but does not directly alter data or crash the service.

Generated by OpenCVE AI on September 18, 2026 at 05:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Uber Kraken version 0.1.30 or later, where the tag parameter validation is corrected.
  • If an upgrade is not immediately possible, restrict or remove unauthenticated access to the /tags endpoint so that only trusted users can invoke it.
  • Implement explicit path sanitization on the backend to reject any '/../' or percent‑encoded traversal components before resolving the requested file, and ensure the storage root points only to non‑sensitive directories.

Generated by OpenCVE AI on September 18, 2026 at 05:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary files accessible to the testfs backend process.
Title Uber Kraken through 0.1.29 Path Traversal via tag parameter
First Time appeared Uber
Uber kraken
Weaknesses CWE-22
CPEs cpe:2.3:a:uber:kraken:*:*:*:*:*:*:*:*
Vendors & Products Uber
Uber kraken
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T15:41:40.643Z

Reserved: 2026-09-16T19:40:19.438Z

Link: CVE-2026-92791

cve-icon Vulnrichment

Updated: 2026-09-21T15:41:15.296Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:28.627

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-92791

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:15:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')