Path Traversal Vulnerability in Wertheim SafeController Software
CVE-2026-34026

7.1HIGH

What is CVE-2026-34026?

The Wertheim SafeController Software features a path traversal vulnerability within the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. This flaw allows authenticated users, irrespective of their role or permission level, to manipulate file paths using unvalidated input. By exploiting this vulnerability, attackers can traverse outside the designated document directory and access sensitive files, including application logs and binaries, which should remain secure. It’s crucial for organizations using this software to implement necessary security measures and apply updates to mitigate potential risks.

Affected Version(s)

Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christian Hager, SEC Consult Vulnerability Lab
Gorazd Jank, SEC Consult Vulnerability Lab
Philipp Espernberger, SEC Consult Vulnerability Lab
.