SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-14903

HIGH · CVSS 7.7 EPSS 1.04%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Ivanti Xtraction versions prior to 2026.2.1 are vulnerable to a path traversal flaw that enables remote authenticated attackers to access and read arbitrary files outside the web root. This vulnerability poses a significant risk of data exposure, making it critical for organizations using affected versions to prioritize immediate patching. Users of Ivanti Xtraction should assess their systems and implement the necessary updates to mitigate potential data breaches.

CVE
CVE-2026-14903
Severity
HIGH
CVSS
7.7
EPSS
1.04%
Ivanti

Original NVD Description

Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.

Related CVEs

Other vulnerabilities affecting the same vendor(s)