Remote Code Execution Vulnerability in Affected Product by Vendor
CVE-2026-14947

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-14947?

This vulnerability allows an authenticated attacker with high privileges to upload malicious ZIP archives containing directory traversal sequences, such as ../, which can escape the intended extraction directory. This flaw results from improper validation of archive entry paths prior to writing files to disk. By exploiting this vulnerability, attackers may succeed in writing files to arbitrary locations on the server, potentially leading to arbitrary code execution and compromising the entire system.

Affected Version(s)

FDS 102 2.8.0 <= 2.13.3

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.