CVE-2026-8361: Gladinet Triofox Path Traversal in WOSDefaultHttpModule.dll
A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
WOSDefaultHttpModule.dll (Gladinet Triofox)from your environment.If the WOSDefaultHttpModule.dll is not required, remove or disable the module from the host so the vulnerable component is no longer processed.
- Configuration
Configure the web server, reverse proxy, or application gateway to reject or rewrite any requests whose path begins with '/woshome', or disable the module's handling of that path.
Web frontend / WOSDefaultHttpModule.dll URL path handling for /woshome = block requests starting with /woshome - Compensating control
Deploy a WAF or perimeter rule to block path traversal patterns and any requests to paths starting with '/woshome' (for example, block requests containing '../' or other traversal indicators) until the vulnerable component is removed or patched.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8361?
The severity of CVE-2026-8361 is rated high with a score of 7.5.
What kind of vulnerability is CVE-2026-8361?
CVE-2026-8361 is a path traversal vulnerability that exists in WOSDefaultHttpModule.dll.
How can CVE-2026-8361 be exploited?
CVE-2026-8361 can be exploited by processing a URL path that starts with /woshome.
What software is affected by CVE-2026-8361?
Gladinet Triofox software is affected by CVE-2026-8361.
How do I fix CVE-2026-8361?
To fix CVE-2026-8361, update to the latest version of Gladinet Triofox or apply the vendor-recommended patches.