CVE-2026-36500
Critical severity, CVSS 9.1. EPSS: 1.1% chance of exploitation in the next 30 days.
An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request.
Published 2026-06-05. Last modified 2026-06-17.