CVE-2026-19532: Path Traversal in HAVELSAN's Liman MYS
Published Sep 24, 2026
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS allows Path Traversal.
This issue affects Liman MYS: from 2.3.2 before 2.3.4-1124.
Affected Software
1 affected component
HAVELSAN Liman MYS>=2.3.2<2.3.4-1124
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HAVELSAN Liman MYSto a version that resolves this vulnerability.Fixed in 2.3.4-1124
Event History
Sep 24, 2026
CVE Published
via MITRE·11:57 AM
Data Sourced
via MITRE·11:57 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Liman MYS deployments are affected?
The issue affects HAVELSAN Liman MYS versions from 2.3.2 up to, but not including, 2.3.4-1124.
2
Does exploitation require authentication or user interaction?
No. The supplied CVSS vector indicates network exploitation with low attack complexity, no privileges required, and no user interaction.
3
What is the expected security impact?
The supplied CVSS vector indicates limited confidentiality impact, with no integrity or availability impact identified.