What is CVE-2026-19761?
A path traversal vulnerability exists in the MultipartFile.getOriginalFilename function within UploadController.java of DTStack Taier 1.4.0. This flaw allows remote attackers to manipulate the file argument and potentially gain unauthorized access to the file system. Upgrading to a patched version is recommended.
Azərbaycanca: DTStack Taier 1.4.0 versiyasında yerləşən UploadController.java faylındakı MultipartFile.getOriginalFilename funksiyasında path traversal zəifliyi aşkarlanıb. Bu boşluq təcavüzkara arqumenti manipulyasiya edərək uzaqdan fayl sisteminə icazəsiz giriş imkanı verə bilər. Təhlükəsizlik üçün proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: DTStack
FAQ2
Which version of DTStack Taier is affected by CVE-2026-19761?
CVE-2026-19761 affects version 1.4.0 of DTStack Taier.
How can I protect against CVE-2026-19761?
It is recommended to upgrade DTStack Taier to the latest patched version for security.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.