SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-45576

HIGH · CVSS 7.5 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability in zrok allows attackers to manipulate the `zrok2 copy` command to store malicious WebDAV or zrok drive paths, enabling unauthorized file writes outside the intended local filesystem destination. This could lead to data exposure or corruption, making it critical for organizations using versions 0.4.23 to 2.0.2 to prioritize upgrading to version 2.0.3 to mitigate potential risks. Users of this software should act promptly to secure their systems against this high-severity issue.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-45576
Severity
HIGH
CVSS
7.5
EPSS
0.34%

Original NVD Description

zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarget.WriteStream, allowing the sync pipeline to write files outside the selected local filesystem destination root. This issue is fixed in version 2.0.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)