CVE-2026-13716

Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:craftycontrol:crafty_controller:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-11 06:17

Updated : 2026-08-18 18:06


NVD link : CVE-2026-13716

Mitre link : CVE-2026-13716

CVE.ORG link : CVE-2026-13716


JSON object : View

Products Affected

craftycontrol

  • crafty_controller
CWE
CWE-35

Path Traversal: '.../...//'