CVE-2025-59793

CRITICAL

Rocket TRUfusion Enterprise <7.10.5 - Path Traversal

Title source: llm
STIX 2.1

Description

Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, which allows path traversal sequences to be included. This allows writing files to arbitrary local filesystem locations and may subsequently lead to remote code execution.

Scores

CVSS v3 9.9
EPSS 0.0075
EPSS Percentile 73.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-35
Status published
Products (1)
rocketsoftware/trufusion_enterprise < 7.10.5.0
Published Feb 17, 2026
Tracked Since Feb 18, 2026