What is CVE-2026-5491?
This vulnerability allows remote attackers to perform directory traversal on affected DriveLock installations without authentication, leading to disclosure of sensitive information. It is recommended to update DriveLock to the latest patched version to mitigate this issue.
Azərbaycanca: Bu boşluq DriveLock proqramının veb xidmətində autentifikasiya tələb etmədən qovluq keçidi (Directory Traversal) həyata keçirməyə imkan verir, uzaqdan hücumçulara həssas məlumatları əldə etməyə şərait yaradır. Təsirlənən sistemlərdə boşluğu aradan qaldırmaq üçün DriveLock-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: DriveLock
FAQ1
Does an attacker exploiting CVE-2026-5491 need to authenticate to access sensitive information?
No, this vulnerability allows remote attackers to perform directory traversal on the DriveLock web service without authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.