CVE-2026-40027 | abrignoni ALEAPP up to 3.4.0 NQ_Vault.py file_name_from path traversal
A vulnerability, which was classified as critical, was found in abrignoni ALEAPP up to 3.4.0. This issue affects some unknown processing of the file NQ_Vault.py. Executing a manipulation of the argument file_name_from can lead to path traversal.
This vulnerability is registered as CVE-2026-40027. The attack needs to be launched locally. No exploit is available.
It is best practice to apply a patch to resolve this issue.