CVE-2026-27557

An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.

  • Published Sep 16, 2026
  • CVSS 7.5 high
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-27557 at the National Vulnerability Database