PT-2026-5659 · Unknown · Eap Legislator
Marcin Ressel
·
Published
2026-02-02
·
Updated
2026-02-02
·
CVE-2026-1186
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
EAP Legislator versions prior to 2.25a
Description
EAP Legislator is susceptible to a Path Traversal issue within its file extraction functionality. An attacker can craft a malicious zipx archive – the default file type used by the application – and specify an arbitrary path outside the intended directory. Upon opening the crafted file, the application will extract files to the attacker-defined location, potentially including sensitive system areas like the system startup directory.
Recommendations
Update to version 2.25a or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eap Legislator