CVE-2026-86538 carries a CVSS 3.1 base score of 7.5 against knowns, an open-source application. NVD classifies it as CWE-22 (Path Traversal) and states the flaw is fixed in version 0.30.0, meaning all earlier versions are affected. VulnCheck’s KEV feed reports the CVE as exploited, dated September 17, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-86538 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description states the POST /api/templates/preview endpoint contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files. NVD states attackers can supply directory traversal sequences in the endpoint’s templateFile parameter to bypass the application’s path restrictions, and that the resulting file contents — which can include credentials and configuration data — are returned directly in the endpoint’s JSON response. The CVSS vector confirms this requires no authentication and no user interaction (PR:N, UI:N) and impacts confidentiality only (C:H/I:N/A:N).
Evidence and confidence
- Medium confidence — the CVSS 7.5 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), the CWE-22 classification, the fixed version (0.30.0), and the described mechanism all trace to NVD alone in our current ingestion, corroborated by the project’s own GitHub security advisory and fix commit. The exploitation report traces to VulnCheck KEV alone.
Our source data does not carry an EPSS score or percentile for this CVE. No field is in conflict between our two sources.
Why this matters
Path traversal flaws that return file contents directly in an API response — rather than merely confirming a file’s existence — are especially damaging because they hand an unauthenticated attacker a direct read primitive against the server’s filesystem, and NVD explicitly calls out credentials and configuration files as reachable targets. Any organization running a pre-0.30.0 knowns deployment with this endpoint exposed to the internet should treat this as an active, unauthenticated data-exposure risk and prioritize patching.
Frequently Asked Questions
What is CVE-2026-86538?
A CVSS 7.5 path traversal vulnerability (CWE-22) in knowns before version 0.30.0, allowing unauthenticated attackers to read arbitrary files, including credentials and configuration data, via the templateFile parameter of the POST /api/templates/preview endpoint.
Is CVE-2026-86538 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 17, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this? No. NVD’s description and the CVSS vector both confirm this is exploitable without authentication.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Version 0.30.0, per NVD and the project’s own release notes.
Severity, vector, weakness classification, and the described mechanism sourced from the National Vulnerability Database record for CVE-2026-86538, corroborated by the project’s GitHub security advisory and fix commit. Exploitation status and the September 17, 2026 catalog date reported by VulnCheck’s own advisory. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. Aggregated September 20, 2026. See more vulnerability intelligence.