Sceawere

Vulnerability Detail

CVE-2026-15585UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AKINSOFT Wolvox9 ERP Path Traversal

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
AKIN Software Computer Import Export…
Product
AKINSOFT Wolvox9 ERP / KontrolPanel.exe
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal. This issue affects AKINSOFT Wolvox9 ERP / KontrolPanel.exe: from s26.02.17 before 26.02.22.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-18T12:17:23.110Z",
  "pubdate": "2026-08-18T12:17:23.110Z",
  "executiveSummary": "An Improper Limitation of a Pathname to a Restricted Directory vulnerability, commonly known as Path Traversal, has been identified in AKINSOFT Wolvox9 ERP / KontrolPanel.exe.\nThis security flaw enables malicious actors to traverse the filesystem hierarchy and access unauthorized directories and sensitive files outside the intended restricted root directory.\nThe vulnerability specifically impacts the AKINSOFT Wolvox9 ERP / KontrolPanel.exe application, affecting build versions spanning from s26.02.17 up to, but excluding, version 26.02.22.\nSuccessful exploitation of this flaw can lead to unauthorized disclosure of confidential system data, configuration files, or other sensitive assets accessible by the privileges of the running application service.\nThe risk implication is rated as significant, as it exposes the underlying operating system structure to external manipulation without requiring complex interaction, depending on network exposure and service accessibility.\nThreat actors possessing network access to the vulnerable endpoint can leverage crafted requests containing directory traversal sequences (such as dot-dot-slash patterns) to bypass access control mechanisms and retrieve arbitrary files from the host machine.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient sanitization and validation of user-supplied input utilized within file system operations by the KontrolPanel.exe component of AKINSOFT Wolvox9 ERP.\nSpecifically, the application fails to adequately restrict file paths or neutralize relative path sequences such as '../' before passing them to underlying file retrieval APIs.\nThe vulnerable component is identified as KontrolPanel.exe within the AKINSOFT Wolvox9 ERP software suite, specifically targeting versions starting from s26.02.17 and existing prior to version 26.02.22.\nExploitation occurs when an attacker crafts a malicious HTTP request or input payload containing directory traversal tokens. When the KontrolPanel.exe component processes this input to locate and read resources, it resolves the relative path sequences against the root directory.\nDue to the lack of strict boundary enforcement, the resolution mechanism successfully traverses upward through the directory tree, allowing access to files residing outside the intended web root or application directory.\nThe attack flow typically proceeds as follows: 1) The attacker identifies the network service hosting KontrolPanel.exe; 2) The attacker formulates an HTTP request or command containing specially encoded path traversal sequences targeting a sensitive system file; 3) The vulnerable application processes the input without verifying whether the resulting absolute path remains within the permitted containment boundary; 4) The application reads the targeted file from the underlying operating system and returns its contents in the response payload.\nPost-exploitation impact includes the potential extraction of sensitive system configurations, credentials, or internal application data, which can be leveraged for further compromise of the host environment."
}
CVE-2026-15585: AKINSOFT Wolvox9 ERP Path Traversal (HIGH Severity, CVSS: 7.5) - Sceawere