CVE-2026-35077: Arbitrary file delete vulnerability in method ugw-delete-file
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
ugw-delete-file methodfrom your environment.Remove or uninstall the ugw-delete-file method if it is not required by your deployment to eliminate the vulnerability.
- Configuration
Disable the ugw-delete-file method to prevent remote users with user privileges from deleting arbitrary local files until an upstream fix is available.
ugw-delete-file method enabled = false - Compensating control
Restrict network access to the interface or service that exposes the ugw-delete-file method (for example via firewall rules, ACLs, or network segmentation) to trusted management hosts only until a vendor-provided fix is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35077?
CVE-2026-35077 has a severity rating of high at 7.2.
What systems are affected by CVE-2026-35077?
CVE-2026-35077 affects the Mbs-solutions Universal Gateway Firmware.
How do I fix CVE-2026-35077?
To fix CVE-2026-35077, apply the security patch provided by Mbs-solutions for the Universal Gateway Firmware.
What is the risk level of CVE-2026-35077?
CVE-2026-35077 has a risk score of 60, indicating a significant threat.
What can an attacker do with CVE-2026-35077?
An attacker exploiting CVE-2026-35077 can delete arbitrary local files due to insufficient validation of user input.