Low [CVE-2026-93986] Path traversal vulnerability
This low-severity Red Hat Linux advisory covers CVE-2026-93986; related products: Cryostat 4, Red Hat Advanced Cluster Management for Kubernetes 2.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Path traversal vulnerability. Red Hat rates this low (CVSS 3.1).
Weakness: CWE-22.
Affected products named by the advisory: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2.
- < 1.75.1
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Mitigation checklist
- Do not point rclone at untrusted shared content on the backends named in this advisory (Google Photos albums, Dropbox or OneDrive shares, PikPak addurl sources, or iCloud Photos with non-default encoding). For VolSync, keep the rclone secret aimed at an S3-compatible bucket that you control. No additional in-product workaround is required for the documented S3/local usage.
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.