CVE-2026-8043
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8043?
CVE-2026-8043 has a high severity rating due to the potential for information disclosure and client-side attacks.
How do I fix CVE-2026-8043?
To fix CVE-2026-8043, upgrade Ivanti Xtraction to version 2026.2 or later.
What types of attacks can be executed due to CVE-2026-8043?
CVE-2026-8043 can be exploited to perform information disclosure and client-side attacks through arbitrary HTML file creation.
What versions of Ivanti Xtraction are affected by CVE-2026-8043?
CVE-2026-8043 affects all versions of Ivanti Xtraction prior to 2026.2.
Who is affected by CVE-2026-8043?
Remote authenticated attackers may exploit CVE-2026-8043 to access sensitive files and conduct attacks on users.