CVE-2026-104706
CVE-2026-104706 is a high-severity vulnerability with a CVSS 4.0 base score of 8.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-31.
Key facts
- Severity: High (CVSS 4.0 base score 8.4)
- EPSS exploit prediction: 0% (3rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-31
- Published:
- Last modified:
Description
DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs
Frequently asked questions
- What is CVE-2026-104706?
- DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs
- How severe is CVE-2026-104706?
- CVE-2026-104706 has a CVSS 4.0 base score of 8.4, rated high severity.
- Is CVE-2026-104706 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (3rd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-104706?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-104706 published?
- CVE-2026-104706 was published on 2026-10-05 and last updated on 2026-10-06.
References
Other CWE-31 vulnerabilities
- CVE-2024-2044 — Critical (CVSS 9.9): pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session…
- CVE-2024-41376 — High (CVSS 8.8): dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
- CVE-2024-24998 — High (CVSS 8.8): A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker…
- CVE-2026-104810 — High (CVSS 8.4): This vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice…
- CVE-2024-36857 — High (CVSS 7.5): Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
- CVE-2024-35431 — High (CVSS 7.5): ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can…