VDB
CVE-2026-10621
CVE-2026-10621
PUBLISHED
CVSS 7.5 HIGH
Reported by certcc · Published June 2, 2026
Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Collibra | Collibra Platform (SaaS) | 2025.10 |
| Collibra | Collibra Platform (SaaS) | 2025.11 |
| Collibra | Collibra Platform (SaaS) | 2026.02 |
| Collibra | Collibra Platform (SaaS) | 2026.03 |
| Collibra | Collibra Platform (SaaS) | 2026.04 |
| Collibra | Collibra Platform (on-prem) | 2026.03 |
| Collibra | Collibra Platform (on-prem) | 2025.10 |
| Collibra | Collibra Platform (SaaS) | 2025.11, 2026.03, 2026.04 |
| Collibra | Collibra Platform (on-prem) | 2025.10, 2026.03 |
Timeline
- Jun 2, 2026 CVE Published
- Jun 2, 2026 CVE Updated
- Jun 5, 2026 EPSS Score
- Jun 11, 2026 Coalition ESS Score