A vulnerability was found in NSA Emissary up to 8.38.x. It has been declared as critical. This affects an unknown part of the file /api/configuration/ of the component API Endpoint. The manipulation of the argument Name results in path traversal.

This vulnerability is known as CVE-2026-35583. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.