What is CVE-2026-19829?
A path traversal vulnerability exists in the Log File Download Endpoint of wvp-GB28181-pro 2.7.4-20260107. Remote attackers can manipulate the `fileName` argument to read arbitrary files on the system. It is recommended to strengthen input validation in `LogController.java` immediately.
Azərbaycanca: wvp-GB28181-pro 2.7.4-20260107 versiyasında Log fayl yükləmə endpointində path traversal zəifliyi aşkarlanıb. Uzaqdan istismar mümkündür, təcavüzkar `fileName` arqumentini manipulyasiya edərək sistemdəki ixtiyari faylları oxuya bilər. Dərhal `LogController.java` faylındakı giriş doğrulamasını gücləndirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: 648540858
FAQ2
Which version of wvp-GB28181-pro is affected by CVE-2026-19829?
CVE-2026-19829 affects version 2.7.4-20260107 of wvp-GB28181-pro.
Which argument does an attacker manipulate in CVE-2026-19829 to read arbitrary files on the system?
An attacker manipulates the `fileName` argument in the Log File Download Endpoint to read arbitrary files on the system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.