Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-022a
https://thehackernews.com/2024/10/zero-day-alert-three-critical-ivanti.html