PT-2026-22109 · Vitess · Vitess

Neurowinter

·

Publicado

2026-02-26

·

Atualizado

2026-03-25

·

CVE-2026-27969

CVSS v4.0

9.3

Crítica

VetorAV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:L/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Vitess versions prior to 23.0.3 and versions prior to 22.0.4
Description Vitess, a database clustering system for horizontal scaling of MySQL, contains a path traversal issue in the builtinbackupengine component during the backup restoration process. An attacker with read/write access to the backup storage location (such as an S3 bucket) can manipulate backup manifest files. This manipulation allows them to write files to arbitrary locations during a restore operation, potentially gaining unintended or unauthorized access to the production deployment environment. This access could allow the attacker to access sensitive information and execute arbitrary commands. The vulnerability arises from improper validation of file paths within the backup manifest.
Recommendations Versions prior to 23.0.3 should be updated to version 23.0.3 or later. Versions prior to 22.0.4 should be updated to version 22.0.4 or later.

Exploit

Correção

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-78359
AZL-78516
CVE-2026-27969
GHSA-R492-HJGH-C9GW
GO-2026-4570
SUSE-SU-2026:1042-1

Produtos afetados

Vitess