216.73.216.233

CVE-2026-8326

· Published 29/05/2026 13:16 · Modified 29/05/2026 15:39

Labels: CVE-2026-8326 2026-05-29CVE-2026-8326CWE-23[email protected]

Essential information

Published
29/05/2026 13:16
Modified
29/05/2026 15:39
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection.  Depending on implementation, the vulnerability can be exploited by an unauthenticated attacker. This issue affects SparkView: before build 1127.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
remotespark / sparkview cpe:2.3:a:remotespark:sparkview:*:*:*:*:*:*:*:*

References