Unauthorized access to files in T-Systems products
Summary
| CVE | CVE-2026-7185 |
|---|---|
| State | PUBLISHED |
| Assigner | INCIBE |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-06 15:16:41 UTC |
| Updated | 2026-07-06 18:41:46 UTC |
| Description | A validation vulnerability has been identified in certain web features related to file management or upload in several products of the TAO 2.0 suite. This vulnerability could allow an attacker capable of interacting with the affected feature to attempt to access file system resources outside the scope intended by the application. |
Risk And Classification
Primary CVSS: v4.0 6 MEDIUM from [email protected]
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.002920000 probability, percentile 0.209780000 (date 2026-07-08)
Problem Types: CWE-22 | CWE-22 CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 6 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 6 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | T-Systems | Archivo | affected 2602.00 custom | Not specified |
| CNA | T-Systems | Archivo | unaffected 2602.00 | Not specified |
| CNA | T-Systems | MyTAO | affected 2602.00 custom | Not specified |
| CNA | T-Systems | MyTAO | unaffected 2602.00 | Not specified |
| CNA | T-Systems | EStima | affected 2602.00 custom | Not specified |
| CNA | T-Systems | EStima | unaffected 2602.00 | Not specified |
| CNA | T-Systems | Buroweb | affected 2602.00 custom | Not specified |
| CNA | T-Systems | Buroweb | unaffected 2602.00 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.incibe.es/en/incibe-cert/notices/aviso/unauthorized-access-files-t-syst... | [email protected] | www.incibe.es | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: T-Systems’ internal security team (en)
Additional Advisory Data
Solutions
CNA: The vulnerability, reported by the T-Systems team itself, has been fixed in version 2602.0.0 of the affected products. The general recommendation is to update to that version or any later version that includes these fixes.