CVE-2024-36427: Targit Decision Suite

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

The file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authenticated attackers to read or write to server files via a crafted file request. This can allow code execution via a .xview file.

Affected products

  • Targit Decision Suite: version 23.2.15007 only

Published 2024-05-29. Last modified 2026-06-17.