Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
References
| Link | Resource |
|---|---|
| https://gitlab.com/crafty-controller/crafty-4/-/work_items/727 | Exploit Vendor Advisory |
| https://gitlab.com/crafty-controller/crafty-4/-/work_items/740 | Exploit Mitigation Vendor Advisory |
| https://gitlab.com/crafty-controller/crafty-4/-/work_items/727 | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-11 06:17
Updated : 2026-08-18 18:06
NVD link : CVE-2026-13716
Mitre link : CVE-2026-13716
CVE.ORG link : CVE-2026-13716
JSON object : View
Products Affected
craftycontrol
- crafty_controller
CWE
CWE-35
Path Traversal: '.../...//'
