CVE-2026-67970: Path Traversal
Published Aug 3, 2026
·Updated
Incorrect access control in the DSSetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.
Affected Software
1 affected component
nasa cFS=7.0.1
Event History
Aug 3, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-67970?
CVE-2026-67970 has a risk score of 60, indicating a moderate severity level.
2
How do I fix CVE-2026-67970?
To fix CVE-2026-67970, implement proper access control measures to prevent unauthorized path traversal in the DS_SetDestPathCmd() component.
3
What systems are affected by CVE-2026-67970?
CVE-2026-67970 affects the NASA cFS version 7.0.1 specifically.
4
What type of vulnerability is CVE-2026-67970?
CVE-2026-67970 is classified as a Path Traversal vulnerability involving incorrect access control.
5
When was CVE-2026-67970 published?
CVE-2026-67970 was published on August 3, 2026.