CVE-2026-36848 is a directory traversal vulnerability affecting the Gigamon GVOS H-VUE subsystem in GVOS version 5.16.1 and below. The flaw allows path traversal outside the intended directory scope, indicating insufficient restriction of user-supplied path input within the H-VUE component. Based on the available information, a malicious actor could leverage crafted path input to access files or directories not intended to be exposed by the application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-36848 affecting Gigamon GigaVUE-OS/GVOS legacy H-VUE functionality exposed by the persistd web service on port 8089. The repo contains two files: a README with vulnerability/root-cause analysis and one executable script, exploit.py, which is the main entry point. The exploit script uses the requests library to interact directly with the vulnerable HTTP(S) endpoints. Its core capability is unauthenticated path traversal against two routes: `/download/<path>` for arbitrary file read and `/upload/<path>` for arbitrary file write. It constructs traversal strings using repeated `..%2F` segments to escape the intended base directory and then appends an attacker-supplied target path. By default, if no file is specified, it attempts to read `/etc/shadow`. Read results are either printed or saved locally using the server-provided filename from the Content-Disposition header. The write capability uploads a local source file to an arbitrary destination path on the target. In addition, the script includes a `shell()` helper that weaponizes the write primitive by dropping a cron file into `/etc/cron.d/` to execute `/bin/nc -l -v -p 9999 -e /bin/bash` as root. This is intended to provide a root bind shell after cron triggers. There is a minor inconsistency in operator messaging: the script tells the user to connect to port 9991, but the actual payload listens on port 9999. The source also contains an embedded Python bind shell string, but it is never written or executed, so it is effectively dead code. Overall, this is a real exploit rather than a detector. It is operational because it provides working read/write exploitation and a basic post-exploitation payload, but it is not framework-based or highly modular. The attack surface is network/web-based over port 8089, with optional HTTPS support and optional certificate verification control via the `--safe` flag.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.