CVE-2026-2251: Path Traversal leading to Remote Code Execution (RCE)
Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on - https://www.support.xerox.com/en-us/product/core/downloads https://www.support.xerox.com/en-us/product/core/downloads
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2251?
CVE-2026-2251 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-2251?
To fix CVE-2026-2251, update Xerox FreeFlow Core to version 8.0.8 or later as instructed in security bulletins.
What are the potential impacts of CVE-2026-2251?
The exploitation of CVE-2026-2251 can allow an attacker to execute arbitrary code on the server, potentially leading to data loss or compromise.
Which versions of Xerox FreeFlow Core are affected by CVE-2026-2251?
Xerox FreeFlow Core versions up to and including 8.0.7 are affected by CVE-2026-2251.
Is there a workaround for CVE-2026-2251?
There are currently no confirmed workarounds for CVE-2026-2251, so upgrading to a secure version is essential.