CVE-2024-37403: Ivanti Docs@work

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root.

Affected products

  • Ivanti Docs@work: before 2.26.0 (fixed in 2.26.0)

Published 2024-08-07. Last modified 2026-06-17.