The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-35079 represents a critical vulnerability in the ugw-restore method that enables authenticated attackers to delete arbitrary files on affected systems. By exploiting insufficient validation of user-controlled input (CWE-73: External Control of File Name or Path), threat actors with user-level privileges can manipulate restore operations to target and remove files beyond their intended scope. This vulnerability is particularly concerning because it requires only basic user privileges to exploit, making it accessible to insider threats or compromised low-privileged accounts. The impact extends to potential system instability, data loss, and disruption of critical operations depending on which files are targeted for deletion.
While CVE-2026-35079 lacks direct MITRE ATT&CK technique mappings, practitioners using Casky.ai would recognize the underlying attack pattern through skills that detect CWE-73 exploitation indicators. Claude AI's extended reasoning capabilities would flag suspicious restore operation patterns that deviate from normal file recovery workflows—such as requests targeting system directories, configuration files, or log locations outside expected restore paths. Security teams would observe findings related to improper input sanitization, path traversal attempts, and unauthorized file system modifications. Although Casky currently shows zero matching skills for this specific CVE, practitioners should correlate findings with techniques like T1485 (Data Destruction) and T1561 (Disk Wipe) to understand the broader destructive intent and implement compensating controls around file operation monitoring and access restrictions on the ugw-restore functionality.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-35079. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation