Junglewise Threat Intelligence

CVE-2026-8361: Gladinet Triofox Server Agent path traversal in WOSDefaultHttpModule.dll

CVE-2026-8361 · Severity: high · CVSS 7.5 · Published 2026-05-27

Technologies: Gladinet Triofox Server Agent. Vendors: Gladinet.

Executive brief

Gladinet Triofox Server Agent is a software component used to facilitate secure file access and synchronization between local servers and cloud storage. A security flaw in the way the agent handles web requests allows an unauthorized person to bypass directory restrictions and access sensitive files on the host system. This could lead to the exposure of confidential corporate data or system configuration files without requiring any user interaction or login credentials.

Technical details

A path traversal vulnerability exists in the WOSDefaultHttpModule.dll component of Gladinet Triofox Server Agent. The vulnerability is triggered when the GladServerAgentService.exe, which listens on TCP port 7878, processes specially crafted URL paths starting with /woshome. An unauthenticated remote attacker can exploit this by using directory traversal sequences (e.g., ../) to escape the intended web root and access arbitrary files on the underlying file system with the privileges of the service. The flaw is identified as CWE-23 (Relative Path Traversal). At the time of the advisory, the vulnerability was confirmed in version 17.1.10488.57063.

Affected products

  • Gladinet Triofox Server Agent 17.1.10488.57063

Timeline

  • 2026-05-27: disclosed: Initial advisory published by Tenable and NVD.

References

Related threats