CVE-2026-29201: exploitation status and patch state
CVE-2026-29201 · CVSS 4.3 MEDIUM
Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relative file path is passed.
Is CVE-2026-29201 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.