Ghostwire

CVE-2026-29201: Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary...

MEDIUM CVSS 5.5

Published: May 8, 2026 | Last Modified: May 8, 2026

Description

Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relative file path is passed.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (2 articles)

References