A vulnerability, which was classified as critical , has been found in Oinone Pamirs up to 7.2.0 . This vulnerability affects the function request.getParameter of the file LocalFileClient.java of the component RestController . Performing a manipulation of the argument uniqueFileName results in path traversal. This vulnerability was named CVE-2026-8736 . The attack may be carried out on the physical device. In addition, an exploit is available. The vendor was contacted early about this disclosure