CVE detail
CVE-2026-12701
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a relative_path containing embedded traversal sequences (e.g., "looking/normal/../../../../etc/shadow") that escapes the intended export directory during FilesystemExport operations. Because the file content is also user-controlled (uploaded artifact), this allows arbitrary file write to any location writable by the Pulp service user, potentially leading to service compromise or further system exploitation.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 10
- within the 30d window
- Peak daily
- 10
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:42142access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 20, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:42132access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 20, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:42240access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 20, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:42151access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 20, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:42082access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 20, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:42079access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 20, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:42078access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 20, 2026, 3:16 PM - https://access.redhat.com/errata/RHSA-2026:42150access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 20, 2026, 3:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2490703bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJul 20, 2026, 3:16 PM - https://access.redhat.com/security/cve/CVE-2026-12701access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 20, 2026, 3:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16653CVSS 5.5 · Medium
A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder H…
- CVE-2026-13186CVSS 8.1 · High
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is deri…
- CVE-2026-65600CVSS 7.8 · High
Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path traversal in the ReplacePathRegex middleware. When ReplacePat…
- CVE-2026-44192CVSS 6.6 · Medium
A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through i…
- CVE-2026-56844CVSS 8.4 · High
A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlyi…
- CVE-2026-47731CVSS 9.1 · Critical
The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS…