CVE-2026-19827: alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal
A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.java of the component logDetailCat Endpoint. This manipulation of the argument executorAddress causes path traversal. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project closed the issue report as "not planned" without any further explanation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19827?
The severity of CVE-2026-19827 is rated as medium with a score of 5.3.
What is CVE-2026-19827 about?
CVE-2026-19827 involves a path traversal vulnerability in the FileInputStream function of the JobLogController.java in alldatacenter alldata up to version 0.6.8.
How can I fix CVE-2026-19827?
To fix CVE-2026-19827, update the alldatacenter alldata software to a version that is later than 0.6.8 where the vulnerability has been patched.
What components are affected by CVE-2026-19827?
The affected components of CVE-2026-19827 are the alldatacenter alldata and the logDetailCat Endpoint.
What impact does CVE-2026-19827 have?
The impact of CVE-2026-19827 includes the potential for attackers to exploit path traversal vulnerabilities through manipulation of the executorAddress argument.