Path Traversal Vulnerability in DTStack Taier Upload Controller
CVE-2026-19761

5.1MEDIUM

Key Information:

Vendor

Dtstack

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-19761?

A path traversal vulnerability exists in DTStack Taier version 1.4.0, specifically within the MultipartFile.getOriginalFilename function of the UploadController.java component. This issue allows an attacker to manipulate file arguments and potentially access files outside of the intended directory structure. An attacker can initiate this attack remotely, making it imperative for users of this version to upgrade to version 1.5.0, which includes a patch addressing the vulnerability. For details on the patch, refer to the commit identifier 572773c4315e23e51e30115151cb091749a8d03e.

Affected Version(s)

Taier 1.4.0

Taier 1.5.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ku4D3 (VulDB User)
.