CVE-2026-2251
CRIT 9.8Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE.
This issue affects Xerox FreeFlow Core versions up to and including 8.0.7.
Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on - https://www.support.xerox.com/en-us/product/core/downloads
https://www.support.xerox.com/en-us/product/core/downloads
Affected Applications in Environment
8
Flow
v2.0.143.0
130 devices
Flow
v2.0.137.0
2 devices
Flow
v1.3.173.0
7 devices
Flow
v1.3.176.0
9 devices
Flow
v1.3.51.1
1 device
Flow
v1.3.51.0
2 devices
Flow
v1.3.174.0
1 device
Flow
v2.0.148.0
1 device
Affected Devices
152
118B-13
Windows
118B-14
Windows
118B-15
Windows
118B-18
Windows
DESKTOP-2F2IHK3
Windows
DESKTOP-PIEDSC2
Windows
DPADVS-L72018DT
Windows
DPADVS-L72115D7
Windows
DPAGNF-A7412369
Windows
DPAGNF-A741236B
Windows
DPAGNF-A805193T
Windows
DPATHL-835405G
Windows
DPATHL-83540MD
Windows
DPBIOL-MITZI
Windows
DPCDIS-R90ZC0S3
Windows
DPCHEM-5VDSTNE
Windows
DPELED-D81938YB
Windows
DPEMAE-92503DF
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-02
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-03
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-04
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-05
Windows
DPITED-L240-06
Windows
DPITED-L240-06
Windows
DPITED-L240-06
Windows
DPITED-L240-06
Windows
DPITED-L240-06
Windows
DPITED-L240-07
Windows
DPITED-L240-07
Windows
DPITED-L240-07
Windows
DPITED-L240-08
Windows
DPITED-L240-08
Windows
DPITED-L240-08
Windows
DPITED-L240-08
Windows
DPITED-L240-08
Windows
DPITED-L240-08
Windows
DPITED-L240-08
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-09
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-10
Windows
DPITED-L240-11
Windows
DPITED-L240-11
Windows
DPITED-L240-11
Windows
DPITED-L240-11
Windows
DPITED-L240-11
Windows
DPITED-L240-11
Windows
DPITED-L240-11
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-12
Windows
DPITED-L240-13
Windows
DPITED-L240-13
Windows
DPITED-L240-13
Windows
DPITED-L240-13
Windows
DPITED-L240-13
Windows
DPITED-L240-13
Windows
DPITED-L240-13
Windows
DPITED-L240-14
Windows
DPITED-L240-14
Windows
DPITED-L240-14
Windows
DPITED-L240-14
Windows
DPITED-L240-14
Windows
DPITED-L240-14
Windows
DPITED-L240-14
Windows
DPITED-L240-16
Windows
DPITED-L240-16
Windows
DPITED-L240-16
Windows
DPITED-L240-16
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
DPITED-L240-17
Windows
FACHVAC-HP640-2
Windows
FACHVAC-HP640-4
Windows
FACHVAC-HP640-5
Windows
FACHVAC92505LP
Windows
HDFS-MXL9273YJB
Windows
HRU5
Windows
HRU6
Windows
HSWENSON
Windows
KRANDOLPH
Windows