Path Manipulation Vulnerability in ExtremeXOS Utilities
CVE-2026-8170

8.7HIGH

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-8170?

The mv, cp, and rm utilities in the ExtremeXOS shell environment contain a vulnerability that fails to safely canonicalize paths, allowing attackers with low-privilege command-line interface access to create symbolic links pointing to privileged file locations. This misbehavior can enable these attackers to read, alter, or replace critical files, potentially leading to escalated privileges all the way to root access. The vulnerability can be exploited both remotely by users holding low-privilege accounts and locally via the serial console, representing a substantial security risk that may allow persistent changes to the device software stack.

Affected Version(s)

Switch Engine (EXOS) Switch Engine 0 < 31.7.4

Switch Engine (EXOS) Switch Engine 32.0.0 < 32.7.4.15

Switch Engine (EXOS) Switch Engine 33.0.0 < 33.1.100

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Extreme would like to thank Hadrien Barral (Université Gustave Eiffel) and Georges-Axel Jaloyan (French Ministry of the Interior) for responsible disclosure of their findings.
.