CVE-2026-49009

Low severity, CVSS 3.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.

Published 2026-05-27. Last modified 2026-06-17.