Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2026-15392

CVE-2026-15392

None
Open
TLP:CLEAR

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location

NVD CVE.org
Critical Infrastructure

AI Analysis

No AI analysis yet.

Description

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories. Callers of file-based drivers can read or write files outside of the data directory.

Details

EPSS Score
0.16%

5.9th percentile

Confidence
90%
Published
Jul 14, 2026
Last Modified
Jul 15, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.