LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-3067 - Vulnerability Analysis

MediumCVSS: 6.3

Last Updated: February 24, 2026

HummerRisk - Path Traversal

Published: February 24, 2026Updated: February 24, 2026PoC AvailableRemote Exploitable

Overview

HummerRisk <= 1.5.0 contains a path traversal caused by manipulation in extractTarGZ/extractZip functions in Archive Extraction component, letting remote attackers access arbitrary file paths, exploit requires no special privileges.

Severity & Score

Severity: Medium
CVSS Score: 6.3

Impact

Remote attackers can access arbitrary files on the system, potentially leading to sensitive data exposure or system compromise.

Mitigation

Update to the latest version beyond 1.5.0.

Details

CVE ID
CVE-2026-3067
Severity
Medium
CVSS Score
6.3
Type
path_traversal
Status
confirmed

CWE

  • CWE-22

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L