CVE-2025-26692
CVSS 3.0 Score 8.1 of 10 (high)
Details
Published Apr 28, 2025
Updated: Apr 29, 2025
CWE ID 22
Summary
CVE-2025-26692 is a new path traversal vulnerability affecting both Quick Agent V3 and V2. The issue allows unauthenticated attackers to bypass restrictions and access arbitrary files or execute code on the target system, potentially with administrative privileges, due to the software's failure to properly limit file paths. This vulnerability poses a significant risk, especially in environments where these products are running with elevated privileges. Users are encouraged to apply patches or workarounds as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.