CVE Explorer
CVE-2026-8170
The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privilege boundary. An attacker with low-privilege CLI access can create a symbolic link that references a privileged filesystem location and then invoke the affected utilities to read, modify, or replace security-critical files outside of their authorized scope. Under certain conditions, this may enable escalation to root-le
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","platforms":["Switch Engine"],"product":"Switch Engine (EXOS)","vendor":"Extreme Networks","versions":[{"lessThan":"31.7.4","status":"affected","version":"0","versionType":"custom"},{"lessThan":"32.7.4.15","status":"affected","version":"32.0.0","versionType":"custom"},{"lessThan":"33.1.100","status":"affected","version":"33.0.0","versionType":"custom"},{"lessThan":"33.7.1","status":"affected","version":"33.2.0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:53daedf2081b4ae46304aff32983aec774465343d9a9e875a4d953deca6a10cc · sha256:2d5a30ed853e5bfd… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"H…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:53daedf2081b4ae46304aff32983aec774465343d9a9e875a4d953deca6a10cc · sha256:2d5a30ed853e5bfd… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-59","description":"CWE-59: Improper Link Resolution Before File Access ('Link Following')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:53daedf2081b4ae46304aff32983aec774465343d9a9e875a4d953deca6a10cc · sha256:2d5a30ed853e5bfd… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"Extreme Networks Product Security","url":"https://www.extremenetworks.com/support/policies/product-security"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:53daedf2081b4ae46304aff32983aec774465343d9a9e875a4d953deca6a10cc · sha256:2d5a30ed853e5bfd… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.