Unauthenticated Arbitrary File Read Vulnerability in Avid NEXIS Products
CVE-2024-26291
8.7HIGH
Key Information:
- Vendor
Avid
- Vendor
- CVE Published:
- 14 July 2025
What is CVE-2024-26291?
A vulnerability exists in the Avid NEXIS products that allows an attacker to read arbitrary files without authentication. The flaw is in the handling of the 'filename' parameter, which fails to validate paths correctly. This oversight can enable unauthorized users to access sensitive files, potentially exposing critical information. Because the affected applications often run with elevated privileges, the impact of this vulnerability can be severe, affecting the security posture of systems utilizing Avid NEXIS solutions.
Affected Version(s)
Avid NEXIS E-series Linux 0 < 2025.5.1
Avid NEXIS F-series Linux 0 < 2025.5.1
Avid NEXIS PRO+ Linux 0 < 2025.5.1