AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19763

LOW · CVSS 3.8 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The vulnerability in DTStack Taier 1.4.0 affects the FileUtils.deleteDirectory function within ClusterController.java, allowing for path traversal due to improper handling of the clusterName argument. This could enable remote attackers to manipulate file paths, potentially leading to unauthorized access or data exposure. Organizations using this version of the software should prioritize upgrading to version 1.5.0 to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19763
Severity
LOW
CVSS
3.8
EPSS
0.38%
Java

Original NVD Description

A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creation. This manipulation of the argument clusterName causes path traversal. Remote exploitation of the attack is possible. Upgrading to version 1.5.0 can resolve this issue. Patch name: ec8c59c76aceb04ab3080543ab2d9c6a4b674729. The affected component should be upgraded.