Executive brief
Ragic's Enterprise Cloud Database is a cloud-based data management platform used by organizations to store and manage business data. Attackers with administrative privileges can exploit a path traversal flaw to download arbitrary system files, potentially exposing sensitive configuration data, credentials, or customer information stored on the server.
Technical details
The vulnerability is a relative path traversal flaw in Ragic's Enterprise Cloud Database that allows arbitrary file read. An attacker with high-level privileges (administrative access) can craft requests using path traversal sequences to bypass directory restrictions and download arbitrary system files from the server. The vulnerability is network-accessible with no user interaction required, but requires prior authentication with administrative or privileged credentials. An attacker can achieve confidentiality impact by exfiltrating sensitive files. A patch was released on 2026-07-09 or later to remediate this issue.
Affected products
- Ragic Enterprise Cloud Database
Timeline
- 2026-09-09: disclosed
- 2026-07-09: patched