CVE-2022-50890 HIGH

CVE-2022-50890: Owlfiles File Manager 12.0.1 - Path Traversal

Vendor Skyjos
Product Owlfiles File Manager
Weakness CWE-22 · Path traversal
Published January 13, 2026
Last update April 7, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers to access system directories. Attackers can exploit the vulnerability by crafting GET requests with directory traversal sequences to access restricted system directories on the device.

Key dates

02Disclosure timeline

January 13, 2026 CVE published
April 7, 2026 Record updated