# Unauthorized Path Traversal Vulnerability in Legacy Smart Update Manager - CVE-2026-15358 This document addresses an **unauthorized path traversal vulnerability** reported in the monitoring component of RMM Central. **Severity:** High **CVE ID:** CVE-2026-15358 **Affected version(s):** Build 10.5.02 and below **Fixed version(s):** Build 10.5.11 **Fixed on:** August 6, 2026 ## What was the problem? An **unauthorized path traversal vulnerability** was identified in legacy Smart Update Manager on Probe installations. This issue has now been fixed. ## Impact of the Vulnerability An unauthorized path traversal vulnerability on a server allows an attacker to access files or directories outside the intended application directory by manipulating file paths. ## Credits and acknowledgments This vulnerability was reported by **qquynh.** ## How do I fix it? These vulnerabilities have been fixed on **August 6, 2026** and the mitigation is available in the build **10.5.11** with monitoring build **12.9.108**. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the service pack page. [https://www.manageengine.com/remote-monitoring-management/service-packs.html](https://www.manageengine.com/remote-monitoring-management/service-packs.html) ## Help For any further questions or concerns, please reach out to us at [rmmcentral-support@manageengine.com](mailto:rmmcentral-support@manageengine.com)