Junglewise Threat Intelligence

CVE-2026-5966: TeamT5 ThreatSonar Anti-Ransomware arbitrary file deletion via path traversal

CVE-2026-5966 · Severity: high · CVSS 8.1 · Published 2026-04-20

Technologies: TeamT5 ThreatSonar Anti-Ransomware. Vendors: TeamT5.

Executive brief

TeamT5 ThreatSonar Anti-Ransomware, a security solution designed to protect organizations from ransomware attacks, contains a vulnerability that allows for unauthorized file deletion. An authenticated attacker with web access can exploit this flaw to delete critical system files. This could lead to significant service disruptions, loss of security logs, or the disabling of the anti-ransomware protection itself.

Technical details

An arbitrary file deletion vulnerability exists in TeamT5 ThreatSonar Anti-Ransomware due to improper limitation of a pathname to a restricted directory (CWE-22/CWE-23). An authenticated remote attacker with web access can provide specially crafted input containing path traversal sequences (e.g., ../) to target and delete files outside of the intended directory. Successful exploitation allows the attacker to delete arbitrary files on the underlying system, potentially leading to a denial-of-service condition or the removal of critical security configurations. The vulnerability is addressed in version 4.0.0.

Affected products

  • TeamT5 ThreatSonar Anti-Ransomware versions up to (excluding) 4.0.0

Timeline

  • 2026-04-20: disclosed
  • 2026-04-20: advisory

References

Related threats