CVE Explorer
CVE-2026-8326
Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection. Depending on implementation, the vulnerability can be exploited by an unauthenticated attacker.
This issue affects SparkView: before build 1127.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"SparkView","vendor":"Remote Spark (https://www.remotespark.com/)","versions":[{"lessThan":"build 1127","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5397d393848f0a9b9815e991d62bd8abb57101a6f57876bf57e91746484003d8 · sha256:e8ffc7c1864ac3d9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":10,"baseSeverity":"CRITICAL","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5397d393848f0a9b9815e991d62bd8abb57101a6f57876bf57e91746484003d8 · sha256:e8ffc7c1864ac3d9… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-23","description":"CWE-23 Relative path traversal","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5397d393848f0a9b9815e991d62bd8abb57101a6f57876bf57e91746484003d8 · sha256:e8ffc7c1864ac3d9… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["release-notes"],"url":"https://www.remotespark.com/view/new.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5397d393848f0a9b9815e991d62bd8abb57101a6f57876bf57e91746484003d8 · sha256:e8ffc7c1864ac3d9… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.