Junglewise Threat Intelligence

CVE-2026-1020: Gotac Police Statistics Database System path traversal

CVE-2026-1020 · Severity: info · CVSS 5.3 · Published 2026-01-16

Technologies: Gotac Police Statistics Database System. Vendors: Gotac.

Executive brief

The Gotac Police Statistics Database System, used for managing law enforcement data, contains a security flaw that allows unauthorized individuals to view internal system files. An attacker could use this to map out the server's directory structure and potentially access sensitive configuration or system information. This could lead to further targeted attacks against the organization's infrastructure.

Technical details

An absolute path traversal vulnerability (CWE-36) exists in the Gotac Police Statistics Database System through version 1.0.3. The flaw allows an unauthenticated remote attacker to bypass directory restrictions by providing absolute file paths to vulnerable parameters. Successful exploitation enables the attacker to enumerate the system file directory and potentially read sensitive files, though the reported impact is limited to low confidentiality loss. While the CVE was later marked as rejected by the CNA, the technical details indicate a network-based attack vector with no user interaction required.

Affected products

  • Gotac Police Statistics Database System up to and including 1.0.3

Timeline

  • 2026-01-15: advisory: Initial disclosure by TWCERT/CC
  • 2026-01-16: disclosed: NVD publication date
  • 2026-07-30: other: CVE marked as rejected/withdrawn by CNA

Related threats