CVE-2026-5027: exploitation status and patch state
CVE-2026-5027 · CVSS 8.8 HIGH · EPSS 31%
The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').
Is CVE-2026-5027 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 31%.
Public exploit code: none found in monitored sources.