Junglewise Threat Intelligence

CVE-2026-21822: HCLSoftware AppScan 360 path traversal in ASReportService

CVE-2026-21822 · Severity: medium · CVSS 6.3 · Published 2026-09-18

Executive brief

HCLSoftware AppScan 360° is a security testing platform used to scan applications for vulnerabilities. The ASReportService component improperly handles file paths, allowing authenticated attackers to read or write files outside the intended directories on the server, potentially exposing sensitive application data or enabling unauthorized file modifications.

Technical details

A path traversal vulnerability exists in the ASReportService component of HCLSoftware AppScan 360° due to improper validation of file paths. An authenticated attacker can exploit this flaw to access or modify files outside the intended application directory scope using path traversal sequences. The vulnerability requires valid credentials to exploit and affects the file handling logic within the report service functionality. Successful exploitation enables read or write access to arbitrary files within the application's accessible scope.

Affected products

  • HCLSoftware AppScan 360

Timeline

  • 2026-09-18: disclosed

References