CVE-2026-21620: TFTP Path Traversal

Published Feb 20, 2026
·
Updated

Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftpfile modules), erlang otp inets (tftpfile modules), erlang otp tftp (tftpfile modules) allows Relative Path Traversal. This vulnerability is associated with program files lib/tftp/src/tftpfile.erl, src/tftpfile.erl.

This issue affects OTP from OTP 17.0 before OTP 28.3.2, OTP 27.3.4.8 and OTP 26.2.5.17, corresponding to tftp from 1.0 before 1.2.4, 1.2.2.1 and 1.1.1.1; also inets from 5.10 before 7.0.

Affected Software

7 affected componentsFixes available
erlang/otp>=17.0
erlang/otp>=5.10<7.0
erlang/otp>=1.0
erlang/inets>=17.0
erlang/tftp>=17.0
Microsoft azl3 erlang 26.2.5.15-1
Microsoft cbl2 erlang 25.3.2.21-5

Event History

Feb 20, 2026
CVE Published
via MITRE·10:57 AM
Data Sourced
via MITRE·10:57 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Feb 25, 2026
Data Sourced
via Microsoft·09:03 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·09:03 AM
DescriptionSeverity
Updated
via Microsoft·09:03 AM
Affected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-21620?

The severity of CVE-2026-21620 is classified as a high-risk vulnerability due to its potential for unauthorized access through relative path traversal.

2

How do I fix CVE-2026-21620?

To fix CVE-2026-21620, update to the latest version of the Erlang/OTP framework that addresses this vulnerability.

3

Which versions of Erlang/OTP are affected by CVE-2026-21620?

CVE-2026-21620 affects Erlang/OTP versions from 1.0 up to and including 7.0, as well as version 17.0 and later.

4

What impact does CVE-2026-21620 have on TFTP functionality?

CVE-2026-21620 allows attackers to perform a relative path traversal, potentially enabling them to access sensitive files on the server through TFTP functionality.

5

Is CVE-2026-21620 specific to certain modules of Erlang/OTP?

Yes, CVE-2026-21620 specifically involves vulnerabilities in the TFTP file modules of Erlang/OTP.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203