CVE-2026-10621: Collibra Platform On-Prem
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.
Affected products
- Collibra Collibra Platform On-Prem: from 2026.03, before 2026.03.356 (fixed in 2026.03.356); from 2025.10, before 2025.10.399 (fixed in 2025.10.399)
- Collibra Collibra Platform Saas: from 2025.10, before 2025.10.9 (fixed in 2025.10.9); from 2025.11, before 2025.11.7 (fixed in 2025.11.7); from 2026.02, before 2026.02.6 (fixed in 2026.02.6); from 2026.03, before 2026.03.4 (fixed in 2026.03.4); from 2026.04, before 2024.04.5 (fixed in 2024.04.5)
Published 2026-06-02. Last modified 2026-07-22.