CVE-2025-15236

MEDIUM

Quantatw Qoca Aim < 2.7.6 - Absolute Path Traversal

Title source: rule
STIX 2.1

Description

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability.

Scores

CVSS v3 4.3
EPSS 0.0007
EPSS Percentile 20.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-36
Status published
Products (1)
quantatw/qoca_aim < 2.7.6
Published Jan 05, 2026
Tracked Since Feb 18, 2026