An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerability when a new Best Practices Report is saved using a special payload inside the xml input field. The XXE vulnerability is blind since the response doesn't directly display a requested file, but rather returns it inside the name data field when the report is saved. An attacker is able to view restricted operating system files. This issue affects all types of users: administrators or normal users.
Conclusion & alert: CVE-2018-18406 is rated High Exploit Risk (83.4/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 2.03%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.31% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.73% | 2.03% | +1.31% |
| 2 | 2025-03-30 | 1.34% | 0.73% | -0.62% |
| 3 | 2025-03-29 | — | 1.34% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.9 | 3.0 | CRITICAL |
|
3.1 | 6.0 | [email protected] |
| 6.5 | 2.0 | MEDIUM |
|
8.0 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| tufin | securetrack | 18.1 | cpe:2.3:a:tufin:securetrack:18.1:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://forum.tufin.com/support/kc/latest/ | Vendor Advisory |
| https://www.exploit-db.com/exploits/45808 | Exploit Third Party Advisory VDB Entry |
| https://www.tufin.com/ | Vendor Advisory |