ArchiveHandler.readArchiveEntry of the file ArchiveHandler.java of the component Legacy API. Such manipulation of the argument archiveEntryName leads to path traversal.
This vulnerability is listed as CVE-2026-47754. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-47754 | NCEAS Metacat 1.x/2.19.1 Legacy API ArchiveHandler.java ArchiveHandler.readArchiveEntry archiveEntryName path traversal (EUVD-2026-55673)
A vulnerability described as problematic has been identified in NCEAS Metacat 1.x/2.19.1. Affected by this vulnerability is the function
SOCIAL SHARE CARD GENERATOR