CVE-2026-36500

Critical severity, CVSS 9.1. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request.

Published 2026-06-05. Last modified 2026-06-17.