CVE-2026-7185: Unauthorized access to files in T-Systems products
A validation vulnerability has been identified in certain web features related to file management or upload in several products of the TAO 2.0 suite. This vulnerability could allow an attacker capable of interacting with the affected feature to attempt to access file system resources outside the scope intended by the application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2602.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7185?
The severity of CVE-2026-7185 is classified as medium with a CVSS score of 6.
How do I fix CVE-2026-7185?
To fix CVE-2026-7185, update the T-Systems TAO 2.0 suite to the latest patched version that addresses this validation vulnerability.
What type of vulnerability is CVE-2026-7185?
CVE-2026-7185 is classified as a Path Traversal vulnerability.
What products are affected by CVE-2026-7185?
CVE-2026-7185 affects several products within the T-Systems TAO 2.0 suite.
What can an attacker do with CVE-2026-7185?
An attacker exploiting CVE-2026-7185 could potentially access unauthorized file system resources outside the intended scope.