CVE-2026-95140EPSS p46.3%
CVE-2026-95140CVE-2026-95140
Description
kkFileView v5.0.0 through v5.0.2 contains a directory traversal vulnerability in FileController.java. The fileUpload, createFolder and existsFile endpoints accept a "path" parameter that is concatenated into the upload base path without validation, allowing unauthenticated attackers to create arbitrary directories and write arbitrary files outside the intended fileDir root via a crafted multipart request
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
| EPSS | 0.59% probability of exploitation · percentile 46.3% · 2026-10-08T12:00:21Z |
| Last modified | 2026-10-06 |