CVE-2024-26291

Severity CVSS v4.0:
HIGH
Type:
CWE-285 Improper Authorization
Publication date:
14/07/2025
Last modified:
15/07/2025

Description

An Unauthenticated Arbitrary File Read vulnerability affects the<br /> Agent when installed on a system. The parameter filename does not validate the<br /> path thus allowing users to read arbitrary files. As<br /> the application runs with the highest privileges (root/NT_AUTHORITY SYSTEM)<br /> by default attackers are able to obtain sensitive information.<br /> <br /> This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.