Junglewise Threat Intelligence

CVE-2026-82460: Cloud Commander directory traversal in file operations

CVE-2026-82460 · Severity: critical · CVSS 9.8 · Published 2026-08-29

Executive brief

Cloud Commander is a web-based file manager and editor. A path traversal vulnerability in its file-operation and markdown endpoints allows unauthenticated attackers to read, write, move, or copy files outside the configured root directory, potentially exposing sensitive system data or enabling unauthorized modifications to files and configurations.

Technical details

Cloud Commander before version 19.20.2 fails to properly validate and normalize file paths in REST file-operation and markdown endpoints. The vulnerability exists in the path handling logic (root.js and related components) where traversal sequences (e.g., ../) are not sanitized before being resolved against the configured root directory. Attackers can exploit this via network requests without authentication to access arbitrary files on the system. The flaw enables reading sensitive files, writing malicious files, moving files, or copying data outside the intended directory boundary, with a CVSS score of 9.8 indicating critical severity.

Affected products

  • Cloud Commander Cloud Commander before 19.20.2

Timeline

  • 2026-08-29: disclosed
  • 2026: patched: Fixed in version 19.20.2

References