PT-2026-22314 · Xerox · Xerox Freeflow Core

Published

2026-02-27

·

Updated

2026-03-04

·

CVE-2026-2251

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xerox FreeFlow Core versions prior to 8.1.0
Description The software contains a path traversal issue due to improper limitation of a pathname to a restricted directory. This allows unauthorized path traversal, potentially leading to remote code execution (RCE). The issue affects file path inputs where insufficient validation or sanitization allows manipulation to access restricted directories on the server.
Recommendations Upgrade to Xerox FreeFlow Core version 8.1.0.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-2251

Affected Products

Xerox Freeflow Core