Path Traversal Vulnerability in Wertheim SafeController Software
CVE-2026-34030

6.9MEDIUM

What is CVE-2026-34030?

The Wertheim SafeController Software, particularly version 6.15.8328.28014, exhibits a critical flaw due to insufficient validation of branch codes during new branch creation. This weakness allows authenticated users with the appropriate privileges to inject path traversal sequences into the branch code. As the branch code is utilized across various application functions, notably in generating filesystem paths for uploaded files, attackers could manipulate file locations. This manipulation could lead to files being stored in unauthorized directories, depending on the service-account permissions and imposed length restrictions on the branch codes.

Affected Version(s)

Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christian Hager, SEC Consult Vulnerability Lab
Gorazd Jank, SEC Consult Vulnerability Lab
Philipp Espernberger, SEC Consult Vulnerability Lab
.