Junglewise Threat Intelligence

CVE-2026-5491: DriveLock Enterprise Service directory traversal in web service

CVE-2026-5491 · Severity: high · CVSS 7.5 · Published 2026-07-29

Executive brief

DriveLock Enterprise Service, a platform used for endpoint security and device control, contains a flaw that allows unauthorized remote users to access sensitive files on the server. By sending specially crafted requests, an attacker can bypass security restrictions to read internal system data or configuration files. This could lead to the exposure of confidential business information or credentials, potentially compromising the entire security management infrastructure.

Technical details

A directory traversal vulnerability exists in the DriveLock Enterprise Service (DES) web service, which typically listens on TCP port 6067. The vulnerability is caused by improper validation of user-supplied file paths containing directory traversal sequences (e.g., '..') before they are used in file system operations. An unauthenticated remote attacker can exploit this by sending a crafted network request to retrieve sensitive files outside of the intended web directory. Successful exploitation allows for information disclosure in the security context of the service account. Patches are available in versions 24.2.9, 25.1.7, and 25.2.4.

Affected products

  • DriveLock DriveLock Enterprise Service (DES) <= 24.2.8 (fixed in 24.2.9); <= 25.1.6 (fixed in 25.1.7); <= 25.2.3 (fixed in 25.2.4)

Timeline

  • 2026-02-06: disclosed: Vulnerability reported to vendor
  • 2026-02-06: advisory: Vendor security bulletin first published
  • 2026-04-15: advisory: ZDI advisory released
  • 2026-07-29: advisory: NVD publication date

References