CVE-2026-67367
Last modified
CVE-2026-67367 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All versions), SIPLANT V3.1 (All versions < V3.1.4). Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. EPSS estimates a 0.81% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All versions), SIPLANT V3.1 (All versions < V3.1.4). Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SIMOVE Fleetmanager V3.1 | < V3.1.13 |
| Siemens | SIMOVE Fleetmanager V3.2 | < V3.2.4 |
| Siemens | SIMOVE Fleetmanager V3.3 | < V3.3.2 |
| Siemens | SIMOVE Fleetmanager V4.0 | < V4.0.1 |
| Siemens | SIPLANT V1.7 | < * |
| Siemens | SIPLANT V2.2 | < * |
| Siemens | SIPLANT V3.0 | < * |
| Siemens | SIPLANT V3.1 | < V3.1.4 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-67367?
How severe is CVE-2026-67367?
How do I fix CVE-2026-67367?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-67361Joomla Extension - j2commerce.com - Unauthenticated file upl…6.9
- CVE-2026-67362Joomla Extension - j2commerce.com - Open redirect in cart co…5.1
- CVE-2026-67363Joomla Extension - balbooa.com - Pre-auth Payment Amount Tam…7.7
- CVE-2026-67364Joomla Extension - balbooa.com - Pre-auth PHP Code Injection…10
- CVE-2026-67365Joomla Extension - icagenda.com - Unauthenticated SQL inject…9.2
- CVE-2026-67366Joomla Extension - icagenda.com - CSRF on frontend registrat…5.3
- CVE-2026-67368Improper link resolution before file access ('link following…8.8
- CVE-2026-67369Out-of-bounds read in SQL Server allows an authorized attack…6.5
- CVE-2026-6737An Exposed IOCTL with Insufficient Access Control vulnerabil…2
- CVE-2026-67370Improper neutralization of special elements used in an sql c…8.8
- CVE-2026-67373Heap-based buffer overflow in SQL Server allows an authorize…8.8
- CVE-2026-67376Integer overflow or wraparound in SQL Server allows an unaut…7.5
Are you affected by CVE-2026-67367?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
