CVE-2026-19827 MEDIUM

CVE-2026-19827: alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal

Vendor Alldatacenter
Product alldata
Weakness CWE-22 · Path traversal
Published August 14, 2026
Last update August 14, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.java of the component logDetailCat Endpoint. This manipulation of the argument executorAddress causes path traversal. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project closed the issue report as "not planned" without any further explanation.

Key dates

02Disclosure timeline

August 14, 2026 CVE published

Related vulnerabilities

04Related CVE