CVE-2026-3067 - Vulnerability Analysis
MediumCVSS: 6.3Last Updated: February 24, 2026
HummerRisk - Path Traversal
Published: February 24, 2026Updated: February 24, 2026PoC AvailableRemote Exploitable
Overview
HummerRisk <= 1.5.0 contains a path traversal caused by manipulation in extractTarGZ/extractZip functions in Archive Extraction component, letting remote attackers access arbitrary file paths, exploit requires no special privileges.
Severity & Score
Severity: Medium
CVSS Score: 6.3
Impact
Remote attackers can access arbitrary files on the system, potentially leading to sensitive data exposure or system compromise.
Mitigation
Update to the latest version beyond 1.5.0.
References
Related Resources
Details
- CVE ID
- CVE-2026-3067
- Severity
- Medium
- CVSS Score
- 6.3
- Type
- path_traversal
- Status
- confirmed
CWE
- CWE-22
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L