Executive brief
Allegra, a project management and collaboration platform, contains a security flaw in its reporting component. An authenticated user can bypass folder restrictions to access sensitive files on the server that they should not be able to see. This could lead to the exposure of system configuration files or other internal data, potentially compromising the security of the entire installation.
Technical details
A directory traversal vulnerability exists in the Allegra project management platform within the 'exportReport' method. The flaw is caused by insufficient validation of user-supplied file paths before they are used in server-side file operations. A remote attacker with basic authentication privileges can exploit this by submitting specially crafted path sequences (e.g., dot-dot-slash) to read arbitrary files in the context of the service account running the application. The issue is addressed in Allegra version 9.0.0.
Affected products
- Alltena Allegra Versions prior to 9.0.0
Timeline
- 2026-04-07: disclosed: Vulnerability reported to vendor
- 2026-04-30: patched: Version 9.0.0 released
- 2026-06-11: advisory: Coordinated public release by Zero Day Initiative