confluence_download_attachment of the file /etc/cron.d/ of the component Model Context Protocol. Performing a manipulation of the argument download_path results in path traversal.
This vulnerability is reported as CVE-2026-27825. The attacker must have access to the local network to execute the attack. No exploit exists.
The affected component should be upgraded.
Intelligence View
SOCIAL SHARE CARD GENERATOR