File Tampering Vulnerability in Crafty Controller by Crafty Controller
CVE-2026-0805
8.2HIGH
What is CVE-2026-0805?
An input neutralization vulnerability discovered in the Backup Configuration component of the Crafty Controller software permits an authenticated remote attacker to exploit path traversal techniques. This exploitation can lead to unauthorized file tampering and potentially allow for the execution of arbitrary code on the server. The vulnerability emphasizes the importance of stringent input validation measures to ensure overall security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Crafty Controller 4.5.0 < 4.8.0
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thank you to [Rozza / rchar](https://gitlab.com/rchar) on GitLab for reporting this issue.
