CVE-2026-1186: Path Traversal in EAP Legislator
EAP Legislator is vulnerable to Path Traversal in file extraction functionality. Attacker can prepare zipx archive (default file type used by the Legislator application) and choose arbitrary path outside the intended directory (e.x. system startup) where files will be extracted by the victim upon opening the file. This issue was fixed in version 2.25a.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1186?
CVE-2026-1186 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to file systems.
How do I fix CVE-2026-1186?
To fix CVE-2026-1186, upgrade EAP Legislator to version 2.25a or later, which addresses the path traversal issue.
What type of attack is CVE-2026-1186 associated with?
CVE-2026-1186 is associated with path traversal attacks allowing unauthorized file extraction to arbitrary locations.
Who is affected by CVE-2026-1186?
Users of EAP Legislator versions up to 2.25a are affected by CVE-2026-1186.
What is the impact of CVE-2026-1186?
The impact of CVE-2026-1186 includes the potential for an attacker to manipulate file extraction paths, leading to sensitive file exposure.