Junglewise Threat Intelligence

CVE-2025-59709: Kovai BizTalk360 directory traversal and arbitrary file read

CVE-2025-59709 · Severity: medium · CVSS 6.8 · Published 2026-04-03

Technologies: Kovai Biztalk360. Vendors: Kovai.

Executive brief

BizTalk360 is a management and monitoring platform for Microsoft BizTalk Server environments. A security vulnerability allows an administrative user to bypass directory restrictions to read sensitive files on the server or force the system to authenticate against external malicious services. This could lead to the exposure of confidential system data or the theft of service credentials, potentially compromising the underlying Windows server.

Technical details

A directory traversal vulnerability exists in BizTalk360 versions prior to 11.6.3963.2611. The issue stems from the mishandling of user-provided input in paths used by the server to read files. An attacker with 'Super User' or administrative privileges can exploit this to access files outside of the intended web directory or coerce the service into performing NTLM authentication against an attacker-controlled listener. While the NVD classifies this as requiring high privileges (PR:H), related research indicates that insufficient access controls on WCF services in the same product suite may allow broader exploitation. The vulnerability was fully addressed in version 11.6.3963.2611 after an initial fix in version 11.6 was found to be bypassable.

Affected products

  • Kovai.co BizTalk360 < 11.6.3963.2611

Timeline

  • 2025-06-27: other: First contact with vendor
  • 2025-10-31: patched: Initial insufficient fix in version 11.6
  • 2025-12-03: patched: Final fix in version 11.6.3963.2611
  • 2026-04-03: disclosed: Public advisory release

References

Related threats