Junglewise Threat Intelligence

CVE-2026-8326: Remote Spark SparkView path traversal in RDP drive redirection

CVE-2026-8326 · Severity: info · CVSS 10 · Published 2026-05-29

Executive brief

Remote Spark SparkView, a solution used for browser-based remote desktop access, contains a critical security flaw in its RDP drive redirection feature. This vulnerability allows an attacker to read or write any file on the underlying system with administrative (root) privileges. In practice, this allows a remote attacker to take full control of the server, potentially leading to data theft, service disruption, or the installation of malicious software.

Technical details

A path traversal vulnerability (CWE-23) exists in the RDP drive redirection component of Remote Spark SparkView. The flaw allows for arbitrary file read and write operations across the entire file system with root-level privileges. Depending on the specific deployment and configuration, the vulnerability may be exploitable by a remote, unauthenticated attacker without any user interaction. Successful exploitation typically results in full Remote Code Execution (RCE) on the host system. The issue is resolved in SparkView build 1127 and later.

Affected products

  • Remote Spark SparkView before build 1127

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory

References