high · CVSS v3 7.5 · CVSS v4 8.7
CVE-2026-93468
HGiga OAKlouds contains an arbitrary file read vulnerability caused by relative path traversal. Unauthenticated remote attackers can leverag
Overview
HGiga OAKlouds contains an arbitrary file read vulnerability caused by relative path traversal. Unauthenticated remote attackers can leverage this flaw to access sensitive system files. This poses a significant risk to confidentiality across affected environments.
Description
The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files.
Impact
The vulnerability directly impacts the confidentiality of the system by allowing unauthorized retrieval of sensitive files without authentication. Integrity and availability remain unaffected by this specific flaw. Organizations utilizing the product are at risk of data exposure if exposed to untrusted networks.
Remediation
Apply the official vendor patch or security update provided by HGiga as soon as possible. Restrict network access to the OAKlouds application interface using a Web Application Firewall (WAF) or strict perimeter controls. Monitor system logs for unusual path traversal patterns or unauthorized file access attempts.
Risk context
Rated as a high severity vulnerability with a CVSS v4 score of 8.7, immediate attention is warranted despite the lack of an available EPSS rating. Internet-facing deployments should be prioritized for mitigation.
Affected products
- HGiga OAKlouds
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 7.5
- CVSS v4
- 8.7
- EPSS
- —