Path Traversal Vulnerability in DigiDoc4 Client by Estonian Information System Authority
CVE-2026-70383
8.4HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 20 August 2026
What is CVE-2026-70383?
The DigiDoc4 Client developed by the Estonian Information System Authority is affected by a Path Traversal vulnerability that allows unauthorized access to restricted directories. This flaw can lead to the exposure of sensitive data, as it enables attackers to manipulate pathnames improperly and traverse to directories outside the intended scope. Affected versions include DigiDoc4 Client from 4.0.0 up to, but not including, 4.11.0. Developers and users are encouraged to update to the latest patched version to mitigate this security risk.
Affected Version(s)
DigiDoc4 4.0.0 < 4.11.0
References
CVSS V4
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Siva Aditya Panuganti, Aditya Security Labs
