CVE-2026-82460: Coderaiser Cloudcmd
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory.
Affected products
- Coderaiser Cloudcmd: before 19.20.2 (fixed in 19.20.2)
Published 2026-08-29. Last modified 2026-09-24.