CVE-2026-2493
IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of IceWarp. Authentication is not required to exploit this vulnerability.
The specific flaw exists within handling of the ticket parameter provided to the collaboration endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-25440.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.93%
- Percentile among all scored CVEs: 90
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1190Exploit Public-Facing Applicationinitial access95 % - Primary impact
T1005Data from Local Systemcollection90 %
Vulnerabilidad de Directory Traversal (CWE-22) en endpoint remoto sin autenticación (AV:N/PR:N/UI:N) que permite lectura no autorizada de ficheros sensibles en el contexto del servidor.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-22
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-2493",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-2493",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-16T15:26:38.414719Z"
}
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "zdi-disclosures@trendmicro.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "zdi-disclosures@trendmicro.com",
"affectedData": [
{
"vendor": "IceWarp",
"product": "IceWarp",
"versions": [
{
"status": "affected",
"version": "14.2.0.10"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-03-16T14:19:30.700",
"references": [
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-26-130/",
"source": "zdi-disclosures@trendmicro.com"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "zdi-disclosures@trendmicro.com",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of IceWarp. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within handling of the ticket parameter provided to the collaboration endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-25440."
},
{
"lang": "es",
"value": "Vulnerabilidad de revelación de información por salto de directorio en la colaboración de IceWarp. Esta vulnerabilidad permite a atacantes remotos revelar información sensible en instalaciones afectadas de IceWarp. La autenticación no es necesaria para explotar esta vulnerabilidad. La falla específica existe en el manejo del parámetro ticket proporcionado al endpoint de colaboración. El problema resulta de la falta de validación adecuada de una ruta proporcionada por el usuario antes de usarla en operaciones de archivo. Un atacante puede aprovechar esta vulnerabilidad para revelar información en el contexto de root. Fue ZDI-CAN-25440."
}
],
"lastModified": "2026-06-17T10:31:09.837",
"sourceIdentifier": "zdi-disclosures@trendmicro.com"
}