Junglewise Threat Intelligence

CVE-2026-47754: Metacat unauthenticated path traversal in archiveEntryName parameter

CVE-2026-47754 · Severity: critical · CVSS 9.3 · Published 2026-08-10

Technologies: Metacat.

Executive brief

Metacat is a data repository platform used by research organizations to preserve and share scientific data. A critical vulnerability allows unauthenticated attackers to read any file on the server by exploiting an unsafe parameter in the legacy API, potentially exposing sensitive research data, credentials, and cryptographic keys. This directly impacts the security of research institutions, data preservation initiatives, and the broader DataONE federation network.

Technical details

The vulnerability is an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=read` endpoint in the legacy Metacat 1.x API. The `ArchiveHandler.readArchiveEntry()` method concatenates user-supplied input directly into a filesystem path without sanitization, and the permission check function `hasReadPermission()` is commented out. An unauthenticated remote attacker can craft a single GET request with traversal sequences (e.g., `../`) to read arbitrary files accessible to the Tomcat process. The vulnerability affects Metacat versions 1.x and 2.x through 2.19.1 and was resolved in version 3.0.0 by removing the vulnerable 1.x API entirely. There is no patch for the 2.x branch; upgrading to 3.0.0 or later is required for a permanent fix.

Affected products

  • Metacat Metacat 1.x and 2.x through 2.19.1

Timeline

  • 2026-08-10: disclosed
  • 2024-04: patched: Vulnerability eliminated in Metacat 3.0.0 by removal of legacy 1.x API