Path Traversal Vulnerability in Remote Spark SparkView
CVE-2026-8326

10CRITICAL

What is CVE-2026-8326?

A path traversal vulnerability in Remote Spark's SparkView component allows unauthorized reading and writing of arbitrary files across all directories with root privileges. Consequently, this could lead to remote code execution (RCE), making the system susceptible to attacks. This vulnerability primarily affects the RDP drive redirection feature, enabling unauthenticated attackers to exploit the flaw depending on the system's implementation.

Affected Version(s)

SparkView 0

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Manuel Feifel of InfoGuard Labs
.