
CVE-2026-34790 Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backu… https://www.cve.org/CVERecord?id=CVE-2026-34790
Post summary
The post announces CVE-2026-34790, noting that Endian Firewall versions <=3.3.25 allow authenticated users to delete arbitrary files via directory traversal, and links to the official CVE record.
