High severity7.7NVD Advisory· Published Jul 14, 2026· Updated Aug 6, 2026
CVE-2026-14903
CVE-2026-14903
Description
Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.
Affected products
2Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.