Path Traversal Vulnerability in YeQifu Warehouse Affecting Remote Access
CVE-2026-18903
Key Information:
Badges
What is CVE-2026-18903?
A vulnerability exists in YeQifu Warehouse, specifically within the processing of the FileController.java file. This flaw allows an attacker to manipulate the argument path, resulting in potential path traversal. As this exploit has been publicly disclosed, it exposes the affected systems to remote attacks. Although the vendor was notified about this issue, they did not respond, leaving the vulnerability unaddressed in available versions.
Affected Version(s)
warehouse aaf29962ba407d22d991781de28796ee7b4670e4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
