VYPR
High severity7.7NVD Advisory· Published Jul 14, 2026· Updated Aug 6, 2026

CVE-2026-14903

CVE-2026-14903

Description

Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.

Affected products

2
  • Ivanti/Xtraction2 versions
    cpe:2.3:a:ivanti:xtraction:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ivanti:xtraction:*:*:*:*:*:*:*:*range: <2026.2.1
    • (no CPE)range: <2026.2.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.