Junglewise Threat Intelligence

CVE-2026-78212: 4MOSAn GCB Doctor arbitrary file read via path traversal

CVE-2026-78212 · Severity: high · CVSS 7.5 · Published 2026-08-24

Executive brief

4MOSAn GCB Doctor is a FreeBSD-based security management center used by organizations to monitor and manage their infrastructure. The vulnerability allows unauthenticated attackers to download arbitrary system files by exploiting a relative path traversal flaw, potentially exposing sensitive configuration files, credentials, and other confidential data stored on the affected system.

Technical details

The vulnerability is a relative path traversal flaw (CWE-23) that enables arbitrary file read in 4MOSAn GCB Doctor. The affected component lacks proper input validation or path normalization, allowing unauthenticated remote attackers to construct malicious requests that traverse the filesystem and retrieve files outside the intended directory. The attack is network-reachable and requires no authentication or user interaction. An attacker can read arbitrary files with the privileges of the application process, including system configuration files and sensitive data. The fix is available by upgrading to version 20260621 or later and applying the FreeBSD-GCB Management Center security update.

Affected products

  • 4MOSAn Security Technology GCB Doctor before 20260621

Timeline

  • 2026-08-24: disclosed
  • 2026-06-21: patched: Version 20260621 or later resolves the vulnerability

References

Related threats