CVE-2026-81028 | ZLMediaKit Download File API server/WebApi.cpp downloadFile relative-path path traversal

SecurityVulns

A vulnerability classified as problematic was found in ZLMediaKit. Affected is the function downloadFile of the file server/WebApi.cpp of the component Download File API. Executing a manipulation of the argument relative-path can lead to path traversal.

This vulnerability appears as CVE-2026-81028. The attack may be performed from remote. There is no available exploit.

It is best practice to apply a patch to resolve this issue.VulDB Recent EntriesRead More