Junglewise Threat Intelligence

CVE-2026-9776: ATEN Unizon directory traversal in writeFileToHttpServletResponse

CVE-2026-9776 · Severity: high · CVSS 7.5 · Published 2026-06-24

Technologies: ATEN Unizon. Vendors: ATEN.

Executive brief

ATEN Unizon, a centralized management platform for AV and IT equipment, contains a security flaw that allows unauthorized individuals to access sensitive files on the server. By sending a specially crafted request, an attacker can bypass security restrictions to read any file on the underlying operating system. This could lead to the exposure of system credentials, configuration data, and other confidential information, potentially compromising the entire management network.

Technical details

A directory traversal vulnerability exists in ATEN Unizon within the 'writeFileToHttpServletResponse' method, specifically exposed via the '/rest/history/report/getFile' endpoint. The flaw is caused by insufficient validation of user-supplied file paths before they are used in file system operations. A remote, unauthenticated attacker can exploit this by submitting crafted path sequences (e.g., dot-dot-slash) to access files outside of the intended directory. Because the application runs with NT AUTHORITY\SYSTEM privileges, an attacker can read any file on the host operating system. The issue is addressed in firmware version V2.7.264.001.

Affected products

  • ATEN Unizon 2.7.262.002

Timeline

  • 2026-03-13: disclosed: Vulnerability reported to vendor
  • 2026-04-15: patched: Firmware V2.7.264.001 released
  • 2026-06-24: advisory: Coordinated public release of advisory

References

Related threats