CVE-2026-7024General

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unknown functionality of the file sims-master/src/web/servlet/file/DeleteFileServlet.java of the component deleteFileServlet Endpoint. Executing a manipulation of the argument filename can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-26: 3Technical Details · 2026-04-26: 104-26
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7024 A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unknown functionality of the file sims-master/src/w… https://www.cve.org/CVERecord?id=CVE-2026-7024

    Post summary

    The post announces the discovery of CVE‑2026‑7024 in the rawchen sims project, providing minimal context but no exploit details or remediation guidance.

    00000135
    57.3K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7024 📊 Severity: 5.4 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7024 #CVE-2026-7024 #CVE #Medium #CyberSecurity #InfoSec https://t.co/atpmqIzGHn

    Post summary

    The tweet merely announces CVE‑2026‑7024 with basic severity and risk information, without any technical detail, PoC, exploit, or patch discussion.

    0000044
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7024 Path Traversal in rawchen sims DeleteFileServlet Endpoint via Filename Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7024

    Post summary

    The snippet announces CVE-2026-7024, identifies it as a path traversal vulnerability via filename manipulation, but provides no information on PoC, exploitation, patches, or active attacks.

    0000052
    4.0K followersView on X

Explore more