CVE-2025-59711: Kovai BIZTALK360

High severity, CVSS 8.3. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated attacker is able to write files outside of the destination directory and/or coerce an authentication from the service, aka Directory Traversal.

Affected products

  • Kovai BIZTALK360: before 11.6.3963.2611 (fixed in 11.6.3963.2611)

Published 2026-04-03. Last modified 2026-07-24.