Executive brief
Ivanti Xtraction, a self-service reporting and dashboard solution, is vulnerable to a security flaw that allows authenticated users to access files they should not be able to see. By exploiting this path traversal vulnerability, a remote attacker with basic user credentials can read sensitive system files located outside of the standard web directory. This could lead to the exposure of configuration data, credentials, or other confidential information stored on the server.
Technical details
A path traversal vulnerability (CWE-23) exists in Ivanti Xtraction prior to version 2026.2.1. The flaw is rooted in insufficient validation of user-supplied file paths, allowing an attacker to use special characters (such as '../') to escape the intended web directory. This is a network-based attack that requires low-privilege authentication but no user interaction. Successful exploitation allows the attacker to read arbitrary files on the host operating system with the permissions of the web service. Ivanti has released version 2026.2.1 to address this issue.
Affected products
- Ivanti Xtraction before 2026.2.1
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory