Executive brief
HGiga OAKlouds is a content management platform used to host and manage website pages and bulletins. An unauthenticated attacker can exploit a relative path traversal flaw in the bulletin module to read sensitive system files directly from the server, exposing confidential configuration data, credentials, and other protected information without authentication.
Technical details
The OAKlouds bulletin_v3 module contains a path traversal vulnerability (CWE-23) that allows unauthenticated remote attackers to read arbitrary system files. The vulnerability exists in the bulletin_v3 component versions 2.0 and 3.0 (before version 107 in both cases), where insufficient input validation on relative path parameters enables traversal attacks. An attacker can send specially crafted requests with relative path sequences (e.g., ../) to escape the intended directory and access system files outside the intended scope. No authentication, special interaction, or preconditions are required to exploit this vulnerability. The attacker gains read-only access to sensitive files, potentially exposing credentials, configuration data, and other confidential information. Patches are available: update OAKlouds-bulletin_v3-2.0 and 3.0 to version 107 or later.
Affected products
- HGiga OAKlouds bulletin_v3-2.0 before 107
- HGiga OAKlouds bulletin_v3-3.0 before 107
Timeline
- 2026-09-18: disclosed