CVE-2026-28518
CVE-2026-28518 is a high-severity vulnerability in Volcengine Openviking with a CVSS 3.x base score of 7.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: High (CVSS 3.x base score 7.8)
- CVSS v4: 8.4
- EPSS exploit prediction: 0% (8th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-9296
- Weakness: CWE-22
- Affected product: Volcengine Openviking
- Published:
- Last modified:
Description
OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside the intended import directory. Attackers can craft malicious ZIP archives with traversal sequences, absolute paths, or drive prefixes in member names to overwrite or create arbitrary files with the importing process privileges.
Frequently asked questions
- What is CVE-2026-28518?
- OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside the intended import directory. Attackers can craft malicious ZIP archives with traversal sequences, absolute paths, or drive prefixes in member names to overwrite or create arbitrary files with the importing process privileges.
- How severe is CVE-2026-28518?
- CVE-2026-28518 has a CVSS 3.x base score of 7.8, rated high severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-28518 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (8th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-28518?
- CVE-2026-28518 affects Volcengine Openviking. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-28518?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2026-28518 have an EU (EUVD) identifier?
- Yes. CVE-2026-28518 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-9296.
- When was CVE-2026-28518 published?
- CVE-2026-28518 was published on 2026-03-03 and last updated on 2026-07-14.
References
- https://github.com/volcengine/OpenViking/commit/46b3e76e28b9b3eee73693720c9ec48820228b72
- https://github.com/volcengine/OpenViking/issues/342
- https://www.vulncheck.com/advisories/openviking-ovpack-import-zip-slip-path-traversal
Affected products (1)
- cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:*
More vulnerabilities in Volcengine Openviking
- CVE-2026-40525 — Critical (CVSS 9.1): OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route…
- CVE-2026-22680 — Medium (CVSS 5.3): OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that…
- CVE-2026-34999 — Medium (CVSS 5.3): OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that…
All CVEs affecting Volcengine Openviking →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.