CVE-2026-2328CWE-790
Backend Access Due to Insufficient Input Validation
High · published March 30, 2026
What it is
An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their intended scope via path traversal, resulting in exposure of sensitive information.
The record
Technical detail
- CVSS v3.1
- 7.5 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00309 · 23.3th percentile
- Weakness
- CWE-790 · Improper Filtering of Special Elements
- Published
- 2026-03-30T06:55Z
EPSS history
Timeline