Path Traversal Vulnerability in Wertheim SafeController Software
CVE-2026-34026
What is CVE-2026-34026?
The Wertheim SafeController Software features a path traversal vulnerability within the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. This flaw allows authenticated users, irrespective of their role or permission level, to manipulate file paths using unvalidated input. By exploiting this vulnerability, attackers can traverse outside the designated document directory and access sensitive files, including application logs and binaries, which should remain secure. It’s crucial for organizations using this software to implement necessary security measures and apply updates to mitigate potential risks.
Affected Version(s)
Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
