CVE-2026-27557: Path Traversal in /index.php/view_uploaded_iodd_file
Published Sep 16, 2026
·Updated
An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/viewuploadedioddfile endpoint allowing the SSH server's private keys to be read.
Event History
Sep 16, 2026
CVE Published
via MITRE·07:50 AM
Data Sourced
via MITRE·07:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The issue can be exploited remotely without authentication or user interaction. An attacker needs network access to the affected endpoint.
2
What information could be exposed?
Successful exploitation allows an attacker to read the SSH server's private keys. The provided data does not identify any other specific files or data types that can be accessed.