What is CVE-2026-19762?
This vulnerability exists in DTStack Taier version 1.4.0. The 'Chunk-Check Endpoint' component in 'FileChunkController.java' improperly validates the 'Name' argument, leading to a path traversal attack. Remote exploitation is possible, and immediate software update is recommended.
Azərbaycanca: Bu zəiflik DTStack Taier 1.4.0 versiyasında aşkarlanıb. 'FileChunkController.java' faylındakı 'Chunk-Check Endpoint' komponentində 'Name' parametrinin düzgün yoxlanılmaması səbəbindən path traversal hücumuna yol açır. Uzaqdan istismar mümkündür, təcili olaraq proqram təminatını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: DTStack
FAQ2
Which component in DTStack Taier 1.4.0 is vulnerable to a path traversal attack?
The 'Chunk-Check Endpoint' component in 'FileChunkController.java' is vulnerable to a path traversal attack due to improper validation of the 'Name' argument.
What should be done to protect against CVE-2026-19762?
It is recommended to immediately update the DTStack Taier software.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.