Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE.
This issue affects Xerox FreeFlow Core versions up to and including 8.0.7.
Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on - https://www.support.xerox.com/en-us/product/core/downloads
https://www.support.xerox.com/en-us/product/core/downloads
Metrics
Affected Vendors & Products
References
History
Fri, 27 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xerox
Xerox freeflow Core |
|
| Vendors & Products |
Xerox
Xerox freeflow Core |
Fri, 27 Feb 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on - https://www.support.xerox.com/en-us/product/core/downloads https://www.support.xerox.com/en-us/product/core/downloads | |
| Title | Path Traversal leading to Remote Code Execution (RCE) | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Xerox
Published: 2026-02-27T08:08:52.263Z
Updated: 2026-02-28T04:55:29.310Z
Reserved: 2026-02-09T14:29:07.126Z
Link: CVE-2026-2251
No data.
Status : Awaiting Analysis
Published: 2026-02-27T09:16:16.950
Modified: 2026-02-27T14:06:37.987
Link: CVE-2026-2251
No data.