Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2026-21726

CVE-2026-21726

Medium
Open
TLP:CLEAR

Loki Path Traversal - CVE-2021-36156 Bypass

AI Analysis

· 2 weeks ago

Executive Summary

The Loki Path Traversal - CVE-2021-36156 Bypass vulnerability is a medium-severity issue that can be exploited to read files at the Ruler API endpoint. The likelihood of exploitation is relatively low, but the potential business impact is moderate due to the risk of unauthorized access to sensitive information. The vulnerability can be exploited remotely without any privileges or authentication.

Enhanced Description

The affected systems and components are not explicitly listed, but the vulnerability is specific to the Loki API endpoint /loki/api/v1/rules/{namespace}. The vulnerability is currently open, and no patch or fix has been released yet. The CISA KEV status is 'No', indicating that this vulnerability is not currently being tracked by the CISA Known Exploited Vulnerabilities catalog. The vulnerability was published on 2026-04-15T00:00:00.000000Z, and thanks to Prasanth Sundararajan for reporting this issue.

Exploitation Context

A realistic exploitation scenario involves an attacker sending specially crafted requests to the affected endpoint to read sensitive files, which can be used for reconnaissance or to gain valuable insights into the target system. The attacker's motivation to exploit this vulnerability is likely driven by the desire to access sensitive information, which can be used for malicious purposes such as identity theft, financial fraud, or other types of cybercrime.

Patch Priority

Medium
The patch priority is medium due to the relatively low likelihood of exploitation and the limited impact of the vulnerability. However, it is essential to apply the official patch or fix as soon as it becomes available to prevent potential data breaches and maintain the confidentiality of sensitive information.

Recommended Actions

  • Apply the official patch or fix as soon as it becomes available
  • Implement additional security measures, such as input validation and sanitization, to prevent path traversal attacks
  • Monitor the affected endpoint for suspicious activity and potential exploitation attempts
  • Update the vulnerability management process to include regular checks for similar issues

Suggested Tags

Path Traversal
Information Disclosure
CVE-2021-36156 Bypass

Confidence Assessment

The confidence in the severity rating and exploitation likelihood is based on the CVSS vector and EPSS score. While the CVSS score of 5.3 indicates a medium-severity issue, the EPSS score of 0.00409 suggests a relatively low likelihood of exploitation. However, the potential business impact and the risk of unauthorized access to sensitive information justify a moderate level of concern.

Description

The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this vulnerability.

Details

CVSS Score
5.3
EPSS Score
0.41%

33.7th percentile

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Confidence
90%
Published
Apr 15, 2026
Last Modified
Aug 11, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.