File Name Control Vulnerability in Ivanti Xtraction Product
CVE-2026-8043

9.6CRITICAL

Key Information:

Vendor

Ivanti

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-8043?

An external control of a file name vulnerability in Ivanti Xtraction prior to version 2026.2 enables a remote authenticated attacker to access sensitive files and potentially write malicious HTML files to a web directory. This flaw may result in information disclosure and expose users to client-side attacks. It is crucial for organizations using this software to implement necessary updates to safeguard against potential threats.

Affected Version(s)

Xtraction 2026.2

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.