216.73.216.233

CVE-2026-2251

· Published 27/02/2026 09:16 · Modified 27/02/2026 14:06

Labels: CVE-2026-2251 10b61619-3869-496c-8a1e-f291b0e71e3f2026-02-27CVE-2026-2251CWE-22

Essential information

Published
27/02/2026 09:16
Modified
27/02/2026 14:06
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on - https://www.support.xerox.com/en-us/product/core/downloads https://www.support.xerox.com/en-us/product/core/downloads

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
10b61619-3869-496c-8a1e-f291b0e71e3f
NVD
View on NVD

Affected products (CPE)

ProductCPE
xerox / freeflow core cpe:2.3:a:xerox:freeflow_core:8.0.7:*:*:*:*:*:*:*

References