Unauthenticated Arbitrary File Read Vulnerability in Avid NEXIS Products
CVE-2024-26291
Key Information:
- Vendor
Avid
- Vendor
- CVE Published:
- 14 July 2025
What is CVE-2024-26291?
A vulnerability exists in the Avid NEXIS products that allows an attacker to read arbitrary files without authentication. The flaw is in the handling of the 'filename' parameter, which fails to validate paths correctly. This oversight can enable unauthorized users to access sensitive files, potentially exposing critical information. Because the affected applications often run with elevated privileges, the impact of this vulnerability can be severe, affecting the security posture of systems utilizing Avid NEXIS solutions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Avid NEXIS E-series Linux 0 < 2025.5.1
Avid NEXIS F-series Linux 0 < 2025.5.1
Avid NEXIS PRO+ Linux 0 < 2025.5.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
