What is CVE-2026-47754?
An unauthenticated path traversal vulnerability exists in the `archiveEntryName` parameter of the `action=read` endpoint in Metacat versions 2.x through 2.19.1 and all 1.x versions. This allows remote file reading via the legacy 1.x API. Administrators should immediately upgrade to the latest version and disable the 1.x API as a temporary mitigation.
Azərbaycanca: Metacat məlumat repozitoriya proqram təminatında, xüsusilə 1.x versiyaları və 2.19.1-ə qədər 2.x versiyalarında `archiveEntryName` parametrində autentifikasiya olunmamış `path traversal` zəifliyi aşkarlanıb. Bu, `action=read` endpoint vasitəsilə uzaqdan fayl oxumağa imkan verir. Administratorlar dərhal Metacat-i ən son versiyaya yeniləməli və müvəqqəti olaraq 1.x API-ni deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of Metacat are affected by the CVE-2026-47754 path traversal vulnerability?
The CVE-2026-47754 vulnerability affects all Metacat 1.x versions and 2.x versions through 2.19.1.
What can an attacker do by exploiting CVE-2026-47754?
By exploiting this vulnerability, an unauthenticated attacker can read files remotely using the `archiveEntryName` parameter via the `action=read` endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.