Junglewise Threat Intelligence

CVE-2026-87747: Ragic Enterprise Cloud Database arbitrary file read via path traversal

CVE-2026-87747 · Severity: medium · CVSS 4.9 · Published 2026-09-09

Technologies: Ragic Enterprise Cloud Database. Vendors: Ragic.

Executive brief

Ragic's Enterprise Cloud Database is a cloud-based data management platform used by organizations to store and manage business data. Attackers with administrative privileges can exploit a path traversal flaw to download arbitrary system files, potentially exposing sensitive configuration data, credentials, or customer information stored on the server.

Technical details

The vulnerability is a relative path traversal flaw in Ragic's Enterprise Cloud Database that allows arbitrary file read. An attacker with high-level privileges (administrative access) can craft requests using path traversal sequences to bypass directory restrictions and download arbitrary system files from the server. The vulnerability is network-accessible with no user interaction required, but requires prior authentication with administrative or privileged credentials. An attacker can achieve confidentiality impact by exfiltrating sensitive files. A patch was released on 2026-07-09 or later to remediate this issue.

Affected products

  • Ragic Enterprise Cloud Database

Timeline

  • 2026-09-09: disclosed
  • 2026-07-09: patched

References

Related threats