← Vulnerability feed

Vulnerability record · CVE-2023-34096 · published 8 June 2023

CVE-2023-34096: Thruk panorama.pm path traversal allows arbitrary file upload

Thruk · Thruk

Thruk versions 3.06 and prior fail to filter, validate or sanitize the location parameter in panorama.pm, allowing path traversal via dot and slash characters. An authenticated attacker can write files to any directory with write permissions on the host. A fix is available in version 3.06.2.

8.8 CVSS 3.1 High EPSS 63% · top 0.8% CWE-22 · Path traversal
8.8CVSS 3.1 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References, 12 tagged exploit
17 Jun 2026Last modified by NVD

Description

Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends. In versions 3.06 and prior, the file `panorama.pm` is vulnerable to a Path Traversal vulnerability which allows an attacker to upload a file to any folder which has write permissions on the affected system. The parameter location is not filtered, validated or sanitized and it accepts any kind of characters. For a path traversal attack, the only characters required were the dot (`.`) and the slash (`/`). A fix is available in version 3.06.2.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 8.8 with high confidentiality, integrity and availability impact, public exploit code available, and very high EPSS probability, though not in KEV.

What it is

Thruk versions 3.06 and prior fail to filter, validate or sanitize the location parameter in panorama.pm, allowing path traversal via dot and slash characters. An authenticated attacker can write files to any directory with write permissions on the host. A fix is available in version 3.06.2.

Impact

An attacker can upload arbitrary files to any writable location on the affected system, which can lead to code execution or system compromise depending on where files are written.

Attack surface

Reachable over the network through the Thruk web interface; the CVSS vector indicates low privileges are required and no user interaction is needed.

Exploitation

Public exploit code and a Metasploit-style module are referenced, and EPSS is 0.62682 (99.155th percentile), but the CVE is not listed in CISA KEV.

What to do

  • Upgrade Thruk to version 3.06.2 or later.
  • Restrict network access to the Thruk web interface to trusted management networks.
  • Enforce least privilege on the Thruk service account so it cannot write outside required directories.
  • Audit and remove unnecessary write permissions on directories accessible to the Thruk process.

Detection

  • Monitor Thruk access logs for requests to panorama endpoints containing '../' or encoded traversal sequences.
  • Alert on file creation or modification events in unexpected directories by the Thruk process user.
  • Review web server and application logs for anomalous upload activity from authenticated Thruk users.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/172822/Thruk-Monitoring-Web-Interface-3.06-Path-Traversal.html ExploitThird Party AdvisoryVDB Entry
https://galogetlatorre.blogspot.com/2023/06/cve-2023-34096-path-traversal-thruk.html
https://github.com/galoget/Thruk-CVE-2023-34096
https://github.com/sni/Thruk/blob/1bc5a5804bf9fc22e82a4eadb21a1795954f0867/plugins/plugins-available/panorama/lib/Thruk/ Exploit
https://github.com/sni/Thruk/blob/1bc5a5804bf9fc22e82a4eadb21a1795954f0867/plugins/plugins-available/panorama/lib/Thruk/ Exploit
https://github.com/sni/Thruk/blob/1bc5a5804bf9fc22e82a4eadb21a1795954f0867/plugins/plugins-available/panorama/lib/Thruk/ Exploit
https://github.com/sni/Thruk/blob/1bc5a5804bf9fc22e82a4eadb21a1795954f0867/plugins/plugins-available/panorama/lib/Thruk/ Exploit
https://github.com/sni/Thruk/commit/26de047275c355c5ae2bbbc51b164f0f8bef5c5b Patch
https://github.com/sni/Thruk/commit/cf03f67621b7bb20e2c768bc62b30e976206aa17 Patch
https://github.com/sni/Thruk/security/advisories/GHSA-vhqc-649h-994h ExploitVendor Advisory
https://www.exploit-db.com/exploits/51509
http://packetstormsecurity.com/files/172822/Thruk-Monitoring-Web-Interface-3.06-Path-Traversal.html ExploitThird Party AdvisoryVDB Entry
https://galogetlatorre.blogspot.com/2023/06/cve-2023-34096-path-traversal-thruk.html
https://github.com/galoget/Thruk-CVE-2023-34096
https://github.com/sni/Thruk/blob/1bc5a5804bf9fc22e82a4eadb21a1795954f0867/plugins/plugins-available/panorama/lib/Thruk/ Exploit
https://github.com/sni/Thruk/blob/1bc5a5804bf9fc22e82a4eadb21a1795954f0867/plugins/plugins-available/panorama/lib/Thruk/ Exploit
https://github.com/sni/Thruk/blob/1bc5a5804bf9fc22e82a4eadb21a1795954f0867/plugins/plugins-available/panorama/lib/Thruk/ Exploit
https://github.com/sni/Thruk/blob/1bc5a5804bf9fc22e82a4eadb21a1795954f0867/plugins/plugins-available/panorama/lib/Thruk/ Exploit
https://github.com/sni/Thruk/commit/26de047275c355c5ae2bbbc51b164f0f8bef5c5b Patch
https://github.com/sni/Thruk/commit/cf03f67621b7bb20e2c768bc62b30e976206aa17 Patch
https://github.com/sni/Thruk/security/advisories/GHSA-vhqc-649h-994h ExploitVendor Advisory
https://www.exploit-db.com/exploits/51509

Track CVE-2023-34096 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-23822Thruk path traversal vulnerabilityThruk is a multibackend monitoring webinterface. Prior to 3.12, the Thruk web monitoring application presents a vulnerability in a file upload form t…EPSS 1.4%6.1CVE-2021-35488Thruk cross-site scripting vulnerabilityThruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject a…EPSS 2.8%6.1CVE-2021-35489Thruk cross-site scripting vulnerabilityThruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected XSS via the host or service …EPSS 0.86%5.4CVE-2021-35490Thruk cross-site scripting vulnerabilityThruk before 2.44 allows XSS for a quick command.EPSS 0.48%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed

Source: NIST National Vulnerability Database (record CVE-2023-34096), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.