#Arbitrary File Write
All CosmicBytez Labs articles tagged #Arbitrary File Write, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-89009: WAVLINK Router Unauthenticated Arbitrary File Write
WAVLINK WN535M1/WN535M3 routers let unauthenticated attackers overwrite any file on the device via the root sync_server daemon.
- Security
CVE-2026-48749: Incus Malicious Image Arbitrary File Write and RCE (CVSS 9.9)
Critical Incus flaw lets a specially crafted container image read or write arbitrary host files, leading to remote code execution. Fixed in v7.2.0.
- Security
CVE-2026-48750: Incus Exec-Output Symlink Attack Enables Host File Write (CVSS 9.9)
Critical Incus flaw: if exec-output is a symlink, command output files are written to arbitrary host paths. Fixed in v7.2.0.
- Security
CVE-2026-14289: FacturaONE WooCommerce Plugin Allows Unauthenticated File Write
A critical unauthenticated arbitrary file write vulnerability in the FacturaONE para WooCommerce con VeriFactu plugin (before v5.37) allows attackers to...
- Security
CVE-2026-15265: Tenable Agent Path Traversal — Arbitrary File Write & RCE (CVSS 9.1)
A critical path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and earlier allows a privileged attacker to write arbitrary files outside the...
- Security
CVE-2026-24014: Apache IoTDB DataNode Path Traversal via Trigger JAR Upload
A critical path traversal vulnerability in Apache IoTDB's DataNode RPC interface allows unauthenticated attackers to write arbitrary files outside the...
- Security
CVE-2025-15036: MLflow Path Traversal in Archive Extraction
A critical path traversal vulnerability in MLflow's extract_archive_to_dir function allows attackers to write arbitrary files outside the intended...