CVE-2026-10621
Collibra Collibra Platform (SaaS), Collibra Platform (on-prem)
Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.
- CVSS
- 7.5
- EPSS
- 0.40% 33.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.02