Path Traversal Vulnerability in Xerox FreeFlow Core Software
CVE-2026-2251
9.8CRITICAL
What is CVE-2026-2251?
A vulnerability exists in Xerox FreeFlow Core that allows improper limitation of pathnames, leading to unauthorized access to restricted directories. This path traversal issue can potentially enable remote code execution (RCE), posing a significant risk to the integrity of the system. Users are recommended to upgrade to FreeFlow Core version 8.1.0, which addresses this vulnerability. For detailed guidance, please refer to the official Xerox security bulletin.
Affected Version(s)
FreeFlow Core Windows 0 <= 8.0.7