CVE-2026-10621
Last modified
CVE-2026-10621 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Collibra | Collibra Platform (SaaS) | >= 2025.10, < 2025.10.9 |
| Collibra | Collibra Platform (SaaS) | >= 2025.11, < 2025.11.7 |
| Collibra | Collibra Platform (SaaS) | >= 2026.02, < 2026.02.6 |
| Collibra | Collibra Platform (SaaS) | >= 2026.03, < 2026.03.4 |
| Collibra | Collibra Platform (SaaS) | >= 2026.04, < 2024.04.5 |
| Collibra | Collibra Platform (on-prem) | >= 2026.03, < 2026.03.356 |
| Collibra | Collibra Platform (on-prem) | >= 2025.10, < 2025.10.399 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-10621?
How severe is CVE-2026-10621?
How do I fix CVE-2026-10621?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10611An authentication bypass vulnerability exists in MISP when L…10
- CVE-2026-10616A weakness has been identified in nextlevelbuilder GoClaw up…4.3
- CVE-2026-10617A security vulnerability has been detected in nextlevelbuild…7.3
- CVE-2026-10619A vulnerability was detected in sayan365 student-management-…7.3
- CVE-2026-1062A flaw has been found in xiweicheng TMS up to 2.28.0. This a…9.8
- CVE-2026-10620A flaw has been found in code-projects Student Admission Sys…7.3
- CVE-2026-10622Improper Authentication in REST API in Collibra Agent, allow…8.2
- CVE-2026-10623The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Ass…4.3
- CVE-2026-10624A vulnerability has been found in SourceCodester Human Resou…4.3
- CVE-2026-10628The Points and Rewards for WooCommerce plugin for WordPress …4.3
- CVE-2026-10629SIP signaling stack in Verizon IMS (unspecified version) imp…7.4
- CVE-2026-1063A vulnerability has been found in bastillion-io Bastillion u…4.7
Are you affected by CVE-2026-10621?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
