← back
CVE-2026-35076highCWE-73

Arbitrary file delete vulnerability in method bac-scanresult

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.2epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
In short

A feature called bac-scanresult allows someone with a user account to delete any file on the system because the code doesn't properly check what files the user is trying to delete. This is dangerous because an attacker could remove important system or application files.

Technical detail

The bac-scanresult method fails to validate user-controlled file path input, allowing authenticated attackers to delete arbitrary files via path traversal or direct file specification. Exploitation requires valid user credentials and can result in denial of service or compromise of system integrity through deletion of critical files.

Summary generated and translated by AI from the official description.
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N