/Vulnerability Library

Avid NEXIS Agent - Arbitrary File Read

CVE-2024-26291
Verified

Description

Avid NEXIS E-series, F-series, PRO+, and System Director Appliance (SDA+) before 2025.5.1 contain an unauthenticated arbitrary file read caused by improper validation of the filename parameter, letting unauthenticated attackers read sensitive files, exploit requires no authentication.

Severity

High

CVSS Score

7.5

Exploit Probability

1%

Affected Product

nexis

Published Date

April 22, 2026

Template Author

dhiyaneshdk

CVE-2024-26291.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2024-26291
CWE ID:
cwe-285

References

https://nvd.nist.gov/vuln/detail/CVE-2024-26291https://raeph123.github.io/BlogPosts/Avid_Nexis/Advisory_Avid_Nexus_Agent_Multiple_Vulnerabilities_en.htmlhttps://kb.avid.com/pkb/articles/troubleshooting/en239659

Remediation Steps

Upgrade to Avid NEXIS version 2025.5.1 or later.