CVE-2026-25039
Scille · parsec-cloud
Scille parsec-cloud is susceptible to a path traversal vulnerability via Windows UNC share names, allowing authenticated users to potentially access unauthorized files.
Executive summary
A path traversal vulnerability in Scille parsec-cloud allows authenticated attackers to perform unauthorized file operations, posing a significant risk to data integrity and confidentiality.
Vulnerability
This is a path traversal vulnerability (CWE-40) involving the improper handling of UNC share names. The vulnerability is exploitable by an authenticated user with low privileges.
Business impact
Successful exploitation of this vulnerability could allow an attacker to read or modify sensitive files outside of the intended directory structure. Given the CVSS score of 8.8, this flaw represents a high risk to organizational data security, potentially leading to unauthorized access to confidential information or system compromise.
Remediation
Immediate Action: Update the Scille parsec-cloud software to version 3.3.3-rc.0 or higher to resolve the path traversal flaw.
Proactive Monitoring: Review application access logs for unusual path patterns or attempts to access system files using UNC naming conventions.
Compensating Controls: Implement strict file system permissions and ensure that the application is running with the minimum necessary privileges to limit the impact of potential path traversal.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The high severity of this vulnerability necessitates an immediate update to the patched version. Administrators should prioritize deployment of the fix to prevent potential unauthorized access to sensitive file shares within the environment.