Junglewise Threat Intelligence

CVE-2025-59711: Kovai BizTalk360 directory traversal in upload mechanism

CVE-2025-59711 · Severity: high · CVSS 8.3 · Published 2026-04-03

Technologies: Kovai Biztalk360. Vendors: Kovai.

Executive brief

BizTalk360, a management and monitoring platform for Microsoft BizTalk Server, contains a vulnerability in its file upload system. An authenticated user, including any domain account if the system is domain-joined, can bypass security restrictions to write files to unauthorized locations on the server. This could allow an attacker to disrupt operations, access sensitive data, or potentially take full control of the server.

Technical details

A directory traversal vulnerability exists in the upload mechanism of BizTalk360 due to improper validation of user-supplied input. Authenticated attackers can exploit this by providing manipulated file paths to write arbitrary files outside of the designated destination directory. When combined with other flaws in the application, such as the lack of access controls on sensitive service endpoints (e.g., /UploadFile in AnalyticsDataService), this can be used to upload and subsequently load malicious DLLs. The vulnerability is reachable over the network via WCF services and can be exploited by any authenticated domain account if the application is configured with Windows Authentication. A fix is available in version 11.6.3963.2611.

Affected products

  • Kovai.co BizTalk360 < 11.6.3963.2611

Timeline

  • 2025-06-27: other: First contact with vendor
  • 2025-08-18: patched: Version 11.5 released (partial fix)
  • 2025-12-03: patched: Version 11.6.3963.2611 released (full fix)
  • 2026-04-03: disclosed: Public advisory released

References

Related threats