logo

McAfee v5.6: Arbitrary File Download Flaw

ID: 4a0e6d40-e330-5c6e-bedc-4cfd646bf80e

STIX ID: report--4a0e6d40-e330-5c6e-bedc-4cfd646bf80e

Feed Name: NCC Research

Threat Score
55/100

Date Published: 2026-05-14

Date Updated: 2026-08-01

...
...

McAfee Email and Web Security Appliance v5.6 contains an authenticated arbitrary file download vulnerability that permits any logged-in user (including low-privileged accounts) to retrieve files accessible to the Apache process (for example /etc/passwd); proof-of-concept request and vendor patch information are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.