Ivanti Xtraction Arbitrary File Write and Sensitive File Read Vulnerability

Vulnerability

A vulnerability in Ivanti Xtraction versions prior to 2026.2 allows remote authenticated attackers to read sensitive files and write arbitrary HTML files to a web directory. This issue could lead to information disclosure and potential client-side attacks.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive information and the introduction of malicious HTML files that could be executed in the context of the user's browser.

Remediation

Users can update to Ivanti Xtraction version 2026.2 to address this vulnerability. The update is available through the Ivanti License System (ILS).

Added: May 12, 2026, 3:26 PM
Updated: May 12, 2026, 3:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
5.2
remediation
0.0
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.