VDB

CVE-2026-10621

CVE-2026-10621 PUBLISHED CVSS 7.5 HIGH

Reported by certcc · Published June 2, 2026

Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
CollibraCollibra Platform (SaaS)2025.10
CollibraCollibra Platform (SaaS)2025.11
CollibraCollibra Platform (SaaS)2026.02
CollibraCollibra Platform (SaaS)2026.03
CollibraCollibra Platform (SaaS)2026.04
CollibraCollibra Platform (on-prem)2026.03
CollibraCollibra Platform (on-prem)2025.10
CollibraCollibra Platform (SaaS)2025.11, 2026.03, 2026.04
CollibraCollibra Platform (on-prem)2025.10, 2026.03

Timeline

  • Jun 2, 2026 CVE Published
  • Jun 2, 2026 CVE Updated
  • Jun 5, 2026 EPSS Score
  • Jun 11, 2026 Coalition ESS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›