Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to version 4.10.8
Workaround
No workaround given by the vendor.
References
History
Tue, 11 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arcadia Technology
Arcadia Technology crafty Controller |
|
| Vendors & Products |
Arcadia Technology
Arcadia Technology crafty Controller |
Tue, 11 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution. | |
| Title | Path Traversal: '.../...//' in Crafty Controller | |
| Weaknesses | CWE-35 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-08-11T06:05:12.457Z
Reserved: 2026-06-29T14:04:39.352Z
Link: CVE-2026-13716
No data.
Status : Received
Published: 2026-08-11T06:17:12.870
Modified: 2026-08-11T06:17:12.870
Link: CVE-2026-13716
No data.
OpenCVE Enrichment
Updated: 2026-08-11T07:30:03Z
Weaknesses