CVE-2026-8326

Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection.  Depending on implementation, the vulnerability can be exploited by an unauthenticated attacker. This issue affects SparkView: before build 1127.
CVSS

No CVSS.

Configurations

No configuration.

History

21 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de salto de ruta en Remote Spark (https://www.Remotespark.Com/) SparkView permite la lectura y escritura de archivos arbitrarios en todos los directorios como root. Esto conduce a RCE. El componente afectado es la redirección de unidades RDP. Dependiendo de la implementación, la vulnerabilidad puede ser explotada por un atacante no autenticado. Este problema afecta a SparkView: antes de la compilación 1127.

29 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 13:16

Updated : 2026-07-21 12:10


NVD link : CVE-2026-8326

Mitre link : CVE-2026-8326

CVE.ORG link : CVE-2026-8326


JSON object : View

Products Affected

No product.

CWE
CWE-23

Relative Path Traversal