Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-82460: Cloud Commander allows reading or changing any file

CVE-2026-82460 · published 5 days ago
Summary

The Cloud Commander web tool (versions before 19.20.2) does not correctly check file paths sent to its REST and markdown features. Because of this, a malicious user could trick the system into reading, modifying, moving or copying files outside the intended directory, potentially exposing sensitive data or altering system files. Update to version 19.20.2 or later, or apply the vendor’s patch, to stop this behavior.

What to do
  • Update coderaiser cloudcmd to version 19.20.2 or later.
Affected software
VendorProductAffected versions
coderaiser cloudcmd < 19.20.2
Original advisory text
Cloud Commander before 19.20.2 Directory Traversal via REST and Markdown
Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-82460 · MITRE
Monitor software like this
Free during beta