216.73.217.22

CVE-2026-2731

· Published 19/02/2026 07:17 · Modified 19/02/2026 15:52

Labels: CVE-2026-2731 2026-02-19CVE-2026-2731CWE-22db4dfee8-a97e-4877-bfae-eba6d14a2166

Essential information

Published
19/02/2026 07:17
Modified
19/02/2026 15:52
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers to execute code via simple web requests

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
db4dfee8-a97e-4877-bfae-eba6d14a2166
NVD
View on NVD

Affected products (CPE)

ProductCPE
dynamicweb / dynamicweb cpe:2.3:a:dynamicweb:dynamicweb:8:*:*:*:*:*:*:*
dynamicweb / dynamicweb cpe:2.3:a:dynamicweb:dynamicweb:<9.19.7:*:*:*:*:*:*:*
dynamicweb / dynamicweb cpe:2.3:a:dynamicweb:dynamicweb:<9.20.3:*:*:*:*:*:*:*

References