CVE-2026-42275
8.7OpenZiti · zrok
A symbolic link following vulnerability in the zrok WebDAV drive backend allows remote path traversal and arbitrary file read or write.
Executive summary
An improper limitation of a pathname vulnerability in OpenZiti zrok versions prior to 2.0.2 allows remote unauthenticated users to read and write arbitrary files on the host filesystem.
Vulnerability
This flaw involves UNIX symbolic link following combined with path traversal, where the WebDAV drive backend fails to restrict symlinks pointing outside the shared root, allowing unauthenticated remote access.
Business impact
Successful exploitation of this vulnerability can result in severe data compromise, allowing attackers to read sensitive system files and potentially write or overwrite arbitrary files on the host filesystem. Given the CVSS score of 8.7, this issue presents a high risk to data confidentiality and integrity, which could lead to operational disruption and unauthorized system modification.
Remediation
Immediate Action: Update OpenZiti zrok to version 2.0.2 or later to resolve the symbolic link traversal flaw.
Proactive Monitoring: Monitor file access logs and WebDAV traffic for anomalous requests targeting files outside the designated shared directories.
Compensating Controls: Ensure that the zrok process runs with the principle of least privilege, restricting its OS-level file permissions to limit the scope of potential file overwrites.
Exploitation status
Public Exploit Available: No (no confirmed public exploit or weaponized module currently exists in our tracked sources).
Analyst recommendation
Organizations utilizing OpenZiti zrok must treat this high severity advisory with urgency by deploying the official patch to version 2.0.2 immediately. Because the vulnerability permits remote file read and write operations without authentication, swift remediation is essential to prevent system compromise.