CVE-2026-21620General

LOWCVSS 2.3 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal. This vulnerability is associated with program files lib/tftp/src/tftp_file.erl, src/tftp_file.erl. This issue affects OTP from OTP 17.0 before OTP 28.3.2, OTP 27.3.4.8 and OTP 26.2.5.17, corresponding to tftp from 1.0 before 1.2.4, 1.2.2.1 and 1.1.1.1; also inets from 5.10 before 7.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-20); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-20: 1Mentions · 2026-03-03: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-02-20: 1Technical Details · 2026-03-03: 102-2003-03
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-201
General1
2026-03-031
Patch1
Full discourse2 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Heads-up #Fedora 42 users! 🐧 A critical Erlang update (26.2.5.17) is out for CVE-2026-21620. This fixes a path traversal hole in the TFTP module that could leak private data. Read more: 👉 https://tinyurl.com/ycxf36t9 #Security https://t.co/4evQdXFXdm

    Post summary

    Fedora 42 users are advised to install Erlang update 26.2.5.17 to patch CVE‑2026‑21620, a path traversal vulnerability in the TFTP module that could expose private data.

    0000051
    1.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-21620 Relative Path Traversal in Erlang/OTP TFTP Module from Version 17.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21620 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The message announces CVE-2026-21620, a relative path traversal in Erlang/OTP TFTP module, and provides links to details but offers no exploit, patch, or evidence of active use.

    0000041
    4.0K followersView on X

Explore more