Junglewise Threat Intelligence

CVE-2026-9774: ATEN Unizon directory traversal in updateLicense method

CVE-2026-9774 · Severity: medium · CVSS 5.5 · Published 2026-06-24

Technologies: ATEN Unizon. Vendors: ATEN.

Executive brief

ATEN Unizon, a centralized management platform for AV and IT devices, contains a security flaw that allows an authenticated administrator to delete files on the server. By exploiting this vulnerability, an attacker can remove critical system files, potentially leading to a complete service outage or system instability. This could disrupt business operations and require significant recovery efforts to restore the management platform.

Technical details

A directory traversal vulnerability exists within the `updateLicense` method of the `LicenseController` in ATEN Unizon. The flaw is located in the `/rest/system/license` endpoint handler, where the application fails to properly validate user-supplied filenames during license file operations. An authenticated attacker with administrative privileges can provide a manipulated path to traverse the file system and delete arbitrary files with NT\SYSTEM privileges. This can be used to cause a denial-of-service (DoS) condition by deleting critical application or system files. The issue is addressed in firmware version V2.7.264.001.

Affected products

  • ATEN Unizon 2.7.262.002 and earlier

Timeline

  • 2026-03-13: disclosed: Vulnerability reported to vendor
  • 2026-04-15: patched: Fixed version FW V2.7.264.001 released
  • 2026-06-24: advisory: Coordinated public release of advisory

References

Related threats