Executive brief
A security vulnerability has been identified in T-Systems' TAO 2.0 suite, a platform used for public administration management. The flaw exists in how the software handles file uploads and management, potentially allowing an authorized user to access sensitive files on the server that they should not be able to see. This could lead to the exposure of confidential administrative data or system configuration files.
Technical details
A path traversal vulnerability (CWE-22) exists in the file management and upload features of several T-Systems TAO 2.0 suite products. The issue stems from improper validation of user-supplied input, allowing an attacker with low-level privileges to bypass directory restrictions. By interacting with affected web features, a remote attacker can access file system resources outside the intended application scope. The vulnerability is addressed in version 2602.00 and later.
Affected products
- T-Systems Archivo versions prior to 2602.00
- T-Systems MyTAO versions prior to 2602.00
- T-Systems eStima versions prior to 2602.00
- T-Systems Buroweb versions prior to 2602.00
Timeline
- 2026-06-16: advisory: Initial advisory published by INCIBE-CERT
- 2026-07-06: disclosed: CVE published to NVD dataset
- 2026-06-16: patched: Fix released in version 2602.00