Junglewise Threat Intelligence

CVE-2026-85409: Eleveo Quality Management path traversal in QuestionnaireService

CVE-2026-85409 · Severity: medium · CVSS 6.3 · Published 2026-09-04

Technologies: Eleveo Quality Management. Vendors: Eleveo.

Executive brief

Eleveo Quality Management is a quality assurance and survey platform used by organizations to manage questionnaires and gather feedback. A path traversal vulnerability in the data export function allows a remote attacker to read or manipulate files on the affected system, potentially exposing sensitive data or enabling system compromise.

Technical details

A path traversal vulnerability exists in the QuestionnaireService.runDataExportNow function in Eleveo Quality Management 9.7.0, where the file_name parameter is not properly validated. An unauthenticated remote attacker can inject path traversal sequences (e.g., ../) to access or export arbitrary files outside the intended directory. The vulnerability is remotely exploitable without authentication, and a proof-of-concept exploit is publicly available. No vendor patch has been released as the vendor has not responded to disclosure attempts.

Affected products

  • Eleveo Quality Management 9.7.0

Timeline

  • 2026-09-04: disclosed
  • other: Exploit is publicly available

References

Related threats