CVE-2026-2627

HIGH

Softland FBackup <9.9 - Path Traversal

Title source: llm
STIX 2.1

Description

A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function in the library C:\Program Files\Common Files\microsoft shared\ink\HID.dll of the component Backup/Restore. The manipulation results in link following. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.346279
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.346279
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.752050

Scores

CVSS v3 7.8
EPSS 0.0024
EPSS Percentile 14.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-59
Status published
Products (10)
Softland/FBackup 9.0
Softland/FBackup 9.1
Softland/FBackup 9.2
Softland/FBackup 9.3
Softland/FBackup 9.4
Softland/FBackup 9.5
Softland/FBackup 9.6
Softland/FBackup 9.7
Softland/FBackup 9.8
Softland/FBackup 9.9
Published Feb 17, 2026
Tracked Since Feb 18, 2026