Description
The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated remote arbitrary file read leading to data disclosure
Action: Patch Immediately
AI Analysis

Impact

The vulnerability in HGiga’s OAKlouds Bulletin allows an unauthenticated remote attacker to perform relative path traversal, enabling the reading of arbitrary system files. The flaw maps to CWE‑23: Relative Path Traversal. This can expose sensitive configuration files, secrets, or other critical data, potentially aiding further attacks such as credential theft or persistence.

Affected Systems

HGiga’s OAKlouds Bulletin version 3.2.0 and 3.3.0 are affected. The vendor’s advisory states that versions prior to 107 contain the flaw, while updates to version 107 or later provide a fix.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity of risk. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, one can infer that an attacker can send a crafted HTTP request to a vulnerable endpoint that accepts a file path parameter, thereby accessing files outside the intended directory.

Generated by OpenCVE AI on September 19, 2026 at 20:59 UTC.

Remediation

Vendor Solution

Update OAKlouds-bulletin_v3-2.0 version 107 or later Update OAKlouds-bulletin_v3-3.0 version 107 or later


OpenCVE Recommended Actions

  • Upgrade OAKlouds Bulletin v3.2.0 or v3.3.0 to version 107 or later.
  • If an immediate patch is not available, block external access to the service or disable the endpoint that accepts file path inputs, and enforce network segmentation or ACLs for the affected host.
  • Apply input validation and path normalization so that any file path supplied by a client is resolved to a whitelisted directory and cannot traverse outside that boundary.

Generated by OpenCVE AI on September 19, 2026 at 20:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Hgiga
Hgiga oaklouds-bulletin V3-2.0
Hgiga oaklouds-bulletin V3-3.0
Vendors & Products Hgiga
Hgiga oaklouds-bulletin V3-2.0
Hgiga oaklouds-bulletin V3-3.0

Fri, 18 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files.
Title HGiga|OAKlouds - Arbitrary File Read
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Hgiga Oaklouds-bulletin V3-2.0 Oaklouds-bulletin V3-3.0
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-18T14:31:42.455Z

Reserved: 2026-09-18T01:58:59.380Z

Link: CVE-2026-93468

cve-icon Vulnrichment

Updated: 2026-09-18T14:29:36.351Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T03:16:33.920

Modified: 2026-09-18T19:15:11.780

Link: CVE-2026-93468

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:00:09Z

Weaknesses
  • CWE-23

    Relative Path Traversal