Path Traversal Vulnerability in DigiDoc4 Client by Estonian Information System Authority
CVE-2026-70383

8.4HIGH

What is CVE-2026-70383?

The DigiDoc4 Client developed by the Estonian Information System Authority is affected by a Path Traversal vulnerability that allows unauthorized access to restricted directories. This flaw can lead to the exposure of sensitive data, as it enables attackers to manipulate pathnames improperly and traverse to directories outside the intended scope. Affected versions include DigiDoc4 Client from 4.0.0 up to, but not including, 4.11.0. Developers and users are encouraged to update to the latest patched version to mitigate this security risk.

Affected Version(s)

DigiDoc4 4.0.0 < 4.11.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Siva Aditya Panuganti, Aditya Security Labs
.