CVE-2026-36851: Path Traversal
Published Aug 26, 2026
·Updated
Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.
Affected Software
1 affected component
UnPoller=2.33.0
Event History
Aug 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:16 PM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The available information identifies the password field as the affected input, but does not state whether an attacker must be authenticated or otherwise able to reach a particular UnPoller interface.
2
What is the impact if exploitation succeeds?
Successful exploitation can allow arbitrary file read and network exfiltration. The provided information does not identify which files may be accessible or any network destinations involved.