{
  "threat_severity" : "Moderate",
  "public_date" : "2026-08-11T09:48:35Z",
  "bugzilla" : {
    "description" : "Nozomi Networks Arc: Arc: Arbitrary file deletion via path traversal in Offline archives functionality",
    "id" : "2513847",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2513847"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.0",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H",
    "status" : "draft"
  },
  "cwe" : "CWE-22",
  "details" : [ "A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with administrative credentials for the web interface could submit an archive name containing traversal sequences and delete arbitrary files reachable by the Arc process, which runs with administrative privileges on the host.", "A flaw was found in Arc. This path traversal vulnerability exists within the Offline archives functionality of the local web interface. A local user with administrative credentials can exploit this by submitting an archive name containing special characters, allowing them to delete arbitrary files on the system. The Arc process runs with administrative privileges, leading to a significant impact on system integrity and availability." ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-33922\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-33922\nhttps://security.nozominetworks.com/NN-2026:15-01" ],
  "name" : "CVE-2026-33922",
  "csaw" : false
}