Path Traversal Vulnerability in Metacat Data Repository Software
CVE-2026-47754

9.3CRITICAL

Key Information:

Vendor

Nceas

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-47754?

CVE-2026-47754 is a path traversal vulnerability in the Metacat Data Repository Software, which is primarily used by researchers to preserve, share, and discover data. This vulnerability is present in versions 2.x through 2.19.1 and all 1.x versions of Metacat. It arises from the mishandling of user-supplied input in the archiveEntryName parameter of the action=read endpoint. Specifically, the software concatenates this parameter into a filesystem path without appropriate validation due to the deactivation of the necessary permission checks. As a result, an unauthenticated remote attacker could exploit this flaw to read any file accessible to the Tomcat process by simply sending a GET request.

This vulnerability poses a severe risk to organizations utilizing Metacat, as it can potentially lead to credential theft and exposure of sensitive research data. Attackers could gain access to client certificates and private keys, allowing them to impersonate legitimate nodes within a research federation. Moreover, the potential for unauthorized access to embargoed data and comprehensive reconnaissance of the system infrastructure amplifies the threat. While the vulnerability was mitigated in Metacat version 3.0.0, older versions remain at risk, particularly those that still deploy the legacy 1.x API.

Potential impact of CVE-2026-47754

  1. Credential Theft: The vulnerability allows an attacker to access files that may contain sensitive credentials, which can facilitate unauthorized access to other systems or data repositories.

  2. Data Exposure: There is a significant risk of unauthorized access to confidential or embargoed research data. This could lead to serious breaches of privacy and intellectual property theft, potentially affecting both the integrity and reputation of organizations involved in sensitive research.

  3. System Reconnaissance: Exploiting this vulnerability enables attackers to perform extensive reconnaissance on the system, gathering valuable information about the infrastructure and its security posture, which could be leveraged for further attacks or to deploy malware.

Affected Version(s)

metacat < 3.0.0

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.