CVE-2026-5535: FedML-AI FedML MQTT Message FileUtils.java path traversal
A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtils.java of the component MQTT Message Handler. Performing a manipulation of the argument dataSet results in path traversal. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5535?
CVE-2026-5535 is classified as a critical vulnerability due to its potential for path traversal attacks.
How do I fix CVE-2026-5535?
To fix CVE-2026-5535, upgrade to a version of FedML-AI FedML that is higher than 0.8.9.
What systems are affected by CVE-2026-5535?
CVE-2026-5535 affects FedML-AI FedML versions up to and including 0.8.9.
What types of attacks can CVE-2026-5535 facilitate?
CVE-2026-5535 can facilitate path traversal attacks that may allow unauthorized file access.
Who should be concerned about CVE-2026-5535?
Organizations using the impacted versions of FedML-AI FedML should be concerned about CVE-2026-5535 and take immediate action.