Bug 2513847 (CVE-2026-33922) - CVE-2026-33922 Nozomi Networks Arc: Arc: Arbitrary file deletion via path traversal in Offline archives functionality
Summary: CVE-2026-33922 Nozomi Networks Arc: Arc: Arbitrary file deletion via path tra...
Keywords:
Status: NEW
Alias: CVE-2026-33922
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-11 10:01 UTC by OSIDB Bzimport
Modified: 2026-08-11 16:35 UTC (History)
76 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-11 10:01:18 UTC
A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with administrative credentials for the web interface could submit an archive name containing traversal sequences and delete arbitrary files reachable by the Arc process, which runs with administrative privileges on the host.


Note You need to log in before you can comment on or make changes to this bug.