CVE-2026-104994
Last modified
CVE-2026-104994 is a low-severity vulnerability rated 2.5/10 on the CVSS scale. Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output..
Description
Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-104994?
How severe is CVE-2026-104994?
How do I fix CVE-2026-104994?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-104908MISP contains an improper input validation vulnerability in …7.1
- CVE-2026-104910MISP contains an authorization bypass in the related events …5.3
- CVE-2026-104912MISP contains an authorization flaw in its correlation handl…7.1
- CVE-2026-104914MISP contains an improper access control vulnerability in it…5.3
- CVE-2026-104988A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST…8.1
- CVE-2026-104991Phproject before 1.8.7 contains a missing object-level autho…7.1
- CVE-2026-1050A flaw has been found in risesoft-y9 Digital-Infrastructure …7.3
- CVE-2026-1051The Newsletter – Send awesome emails from WordPress plugin f…4.3
- CVE-2026-10510Cross-Site Scripting (XSS) in GeniexWebView component in Tra…6.1
- CVE-2026-10512The X25519 x86_64 assembly implementation fails to clear the…7.5
- CVE-2026-10513The Webmention plugin for WordPress is vulnerable to Stored …7.2
- CVE-2026-10514A vulnerability has been found in 1Panel-dev CordysCRM up to…2.4
Are you affected by CVE-2026-104994?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
