CVE-2026-49009
LOW 3.1EPSS 0.5%
Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.
- CVSS v3.1
- 3.1 LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N - EPSS
- 0.52% chance of exploitation in the next 30 days, 42th percentile
- Published
- 2026-05-27
- Updated
- 2026-05-28
Proof-of-concept exploits (2)
- j0xh-sec/CVE-2026-490090★ · 2026-06-01
- INTELEON404/CVE-2026-490090★ · 2026-06-06