What is CVE-2026-19763?
A path traversal vulnerability has been identified in the cluster creation functionality of DTStack Taier 1.4.0, specifically within the 'FileUtils.deleteDirectory' function. By manipulating the 'clusterName' argument, a remote attacker could potentially delete arbitrary directories. Users should restrict access to this functionality and apply vendor patches when available.
Azərbaycanca: DTStack Taier 1.4.0 platformasının klaster yaratma funksionallığında 'clusterName' parametri vasitəsilə path traversal zəifliyi aşkarlanıb. Bu, uzaqdan hücum edən şəxsə 'FileUtils.deleteDirectory' funksiyası vasitəsilə ixtiyari kataloqları silməyə imkan verə bilər. İstifadəçilərə bu funksionallığa girişi məhdudlaşdırmaq və düzəliş tətbiq olunana qədər ehtiyat tədbirləri görmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: DTStack
FAQ2
Which version of DTStack Taier is affected by CVE-2026-19763?
CVE-2026-19763 affects DTStack Taier version 1.4.0.
Through which function can an attacker delete arbitrary directories using CVE-2026-19763?
An attacker can delete arbitrary directories through the 'FileUtils.deleteDirectory' function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.