DriveLock disclosed two directory traversal information disclosure vulnerabilities in its web services that allow remote, unauthenticated attackers to access sensitive files by supplying crafted paths. The flaws are tracked as CVE-2026-5489 / ZDI-26-285 / ZDI-CAN-28719 and CVE-2026-5491 / ZDI-26-287 / ZDI-CAN-28722, and both stem from improper validation of user-supplied paths before file operations are performed.
The first issue affects the DriveLock web service on TCP port 4568 and carries a CVSS score of 5.3, while the second affects the service on TCP port 6067 by default and is rated 7.5. In both cases, successful exploitation can disclose information accessible to the service account without authentication. DriveLock has released updates to remediate the vulnerabilities, and the disclosures credit the researcher stuxxn.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The Zero Day Initiative publicly disclosed two DriveLock directory traversal information disclosure vulnerabilities, ZDI-26-285 and ZDI-26-287, on April 15, 2026. The issues were credited to stuxxn and described as allowing remote unauthenticated attackers to access sensitive information via improper path validation.
DriveLock released updates to remediate two directory traversal vulnerabilities in its web service, later tracked as CVE-2026-5489 and CVE-2026-5491. The flaws affected services listening on TCP ports 4568 and 6067 by default and could allow remote unauthenticated attackers to disclose sensitive information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
drivelock.help
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.