Path Traversal Vulnerability in PMWeb by PMWeb Inc.
CVE-2026-101082

6.9MEDIUM

Key Information:

Vendor

PMWeb Inc.

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101082?

A path traversal vulnerability has been identified in PMWeb versions 7.x, 8.x, and 2025.x, primarily affecting the 'downloader.aspx' file. This vulnerability allows attackers to manipulate file paths through the FullFileName and FileName parameters, potentially leading to unauthorized file access on the server. The exploit can be executed remotely, and the weakness has been publicly disclosed without any response from the vendor upon notification.

Affected Version(s)

PMWeb 7.*

PMWeb 8.*

PMWeb 2025.*

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

aljaber (VulDB User)
aljaber (VulDB User)
VulDB CNA Team
.