Critical Alert 1 Active Exploit Detected Today

CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower


← Back to CVE List

CVE-2026-9506NVD

Vulnerability Summary

This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the filename parameter to access arbitrary files outside the intended directory on the targeted system.



Successful exploitation of this vulnerability could allow an attacker to read arbitrary sensitive files on the targeted system.
Severity Level
UNKNOWN
Published Date
Jun 8, 2026
Last Modified
Jun 8, 2026
Exploitation Status
????
EPSS Score (30-Day)
0.11%Probability
Root Weakness (CWE)
N/A