Unauthenticated Arbitrary File Read Vulnerability in Meshery by Layer5
CVE-2026-65919

8.7HIGH

Key Information:

Vendor

Meshery

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-65919?

Meshery versions prior to 1.0.57 are susceptible to an unauthenticated arbitrary file read vulnerability. This occurs in the /api/system/fileView and /api/system/fileDownload endpoints, where user-supplied file parameters are passed directly to the operating system's Open method without proper path validation. Malicious actors can exploit this by providing absolute paths or path traversal sequences, enabling them to access sensitive files on the host filesystem without needing authentication, thereby posing a significant security risk.

Affected Version(s)

meshery 0 < 1.0.57

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.