Critical severity9.9NVD Advisory· Published Feb 17, 2026· Updated Apr 3, 2026
CVE-2025-59793
CVE-2025-59793
Description
Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, which allows path traversal sequences to be included. This allows writing files to arbitrary local filesystem locations and may subsequently lead to remote code execution.
Affected products
1- cpe:2.3:a:rocketsoftware:trufusion_enterprise:*:*:*:*:*:*:*:*Range: <7.10.5.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.rcesecurity.com/advisories/cve-2025-59793/nvdExploitThird Party Advisory
- www.rcesecurity.comnvdNot Applicable
- www.rocketsoftware.com/en-us/products/b2b-supply-chain-integration/trufusionnvdProduct
- www.rocketsoftware.com/products/rocket-b2b-supply-chain-integration/rocket-trufusion-enterprisenvdProduct
News mentions
0No linked articles in our index yet.