CVE-2026-66476
Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
CVSS
4.9
Medium
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Published: Jul 27, 2026 · Last modified: Jul 27, 2026 · CWE-22
0.3%EPSS · 30 days0.3%
2026-08-142026-09-11
Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-8570610.0 CRI—
KEV—50GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability7hCVE-2026-90445——
——0An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traverse outside the destination directory, causing the extraction process to write files to arbitrary locations with the privileges of that process. This could allow an attacker to inject fabricated records into the system's stored data or tamper with application configuration.20hCVE-2026-498467.5 HIG—
——0libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".." sequences intact, enabling path traversal in any consumer that later joins the URI with a filesystem path. Version 2.0.11 patches the issue.20hCVE-2026-87910——
——0When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.17hCVE-2026-87984——
——0An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise allowlisted commands to write to arbitrary paths accessible to the Vibe process.1dCVE-2026-87983——
——0An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands. Improper handling of quotation marks during path validation enables files outside the active workspace to be read without user approval.1d