PT-2026-36933 · Nagaagent · Nagaagent

Cpt_Penner

·

Published

2026-05-04

·

Updated

2026-05-05

·

CVE-2026-7784

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RTGS2017 NagaAgent versions prior to 5.1.1
Description Improper processing of the file 'apiserver/routes/extensions.py' within the Skills Endpoint component allows for a remote path traversal attack. This occurs through the manipulation of the Name argument. Path traversal is a technique that allows an attacker to access files and directories that are stored outside the web root folder.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-7784

Affected Products

Nagaagent