File Name Control Vulnerability in Ivanti Xtraction Product
CVE-2026-8043
9.6CRITICAL
What is CVE-2026-8043?
An external control of a file name vulnerability in Ivanti Xtraction prior to version 2026.2 enables a remote authenticated attacker to access sensitive files and potentially write malicious HTML files to a web directory. This flaw may result in information disclosure and expose users to client-side attacks. It is crucial for organizations using this software to implement necessary updates to safeguard against potential threats.
Affected Version(s)
Xtraction 2026.2