CVE-2026-2251

Published Feb 27, 2026

Last updated 15 days ago

Overview

Description
Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on - https://www.support.xerox.com/en-us/product/core/downloads https://www.support.xerox.com/en-us/product/core/downloads
Source
10b61619-3869-496c-8a1e-f291b0e71e3f
NVD status
Analyzed
Products
freeflow_core

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

10b61619-3869-496c-8a1e-f291b0e71e3f
CWE-22

Social media

Hype score
Not currently trending

Configurations