Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-5027

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').
Exploit prediction scoring system (EPSS) score
EPSS Score 0.314
EPSS Ranking 98.1%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-5027


Contact Us

Shodan ® - All rights reserved