# Path Traversal Flaw Hits LANSCOPE Endpoint Manager

Published: 2026-02-24 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/8dfadf1e-19b5-52ce-bfcc-db3f32a05759/path-traversal-flaw-hits-lanscope-endpoint-manager

> A critical path traversal vulnerability in MOTEX LANSCOPE Endpoint Manager on-premises sub-manager server can allow arbitrary code execution.

IPA/JVN disclosed a path traversal vulnerability (CVE-2026-25785, CVSS v3 9.8) affecting the sub-manager server component of MOTEX's LANSCOPE Endpoint Manager on-premises edition, version 9.4.7.3 and earlier. The flaw allows an attacker to tamper with arbitrary files on the Windows system hosting the product, which can lead to arbitrary code execution on the affected host.

The cloud version of LANSCOPE Endpoint Manager is not affected by this issue. No evidence of active exploitation is mentioned in the advisory; the notice is a vendor-coordinated disclosure urging administrators to update to the patched version as soon as it becomes available from the developer.

## Mentioned in this report

- Vulnerabilities: CVE-2026-25785

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/20260225-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8dfadf1e-19b5-52ce-bfcc-db3f32a05759/path-traversal-flaw-hits-lanscope-endpoint-manager.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
