Ivanti Xtraction Arbitrary File Write and Sensitive File Read Vulnerability
Vulnerability
A vulnerability in Ivanti Xtraction versions prior to 2026.2 allows remote authenticated attackers to read sensitive files and write arbitrary HTML files to a web directory. This issue could lead to information disclosure and potential client-side attacks.
Impact
Exploitation of this vulnerability could result in unauthorized access to sensitive information and the introduction of malicious HTML files that could be executed in the context of the user's browser.
Remediation
Users can update to Ivanti Xtraction version 2026.2 to address this vulnerability. The update is available through the Ivanti License System (ILS).
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
