CVE-2026-9776 Details
Description
ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the writeFileToHttpServletResponse method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-28505.
A directory traversal vulnerability allowing information disclosure has been identified in ATEN Unizon. This issue arises in the writeFileToHttpServletResponse method, where user-supplied paths are not properly validated before being used in file operations. As a result, remote attackers can exploit this vulnerability to read arbitrary files from the filesystem with NT\SYSTEM privileges. The vulnerability exists in the /rest/history/report/getFile endpoint and does not require authentication.
ATEN has released a security update to address this vulnerability. The fixed version is FW V2.7.264.001, released on April 15, 2026.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.aten.com/global/en/supportcenter/info/security-advisory/29/ | [email protected] | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-26-380/ | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| aten unizon | < 2.7.264 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 27, 2026 | Initial Analysis | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |