Unauthorized Access Vulnerability in IoTSharp's Blob Storage Controller
CVE-2026-71262

9.8CRITICAL

Key Information:

Vendor

Iotsharp

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71262?

The BlobStorageController in IoTSharp lacks proper authorization controls, exposing critical upload, download, modification, and deletion endpoints to unauthorized access. Without an [Authorize] attribute and missing global authorization policies, these endpoints can be exploited by remote attackers. The absence of sanitization for path and filename parameters creates a pathway for path traversal vulnerabilities, allowing attackers to not only manipulate files within the intended storage but also reach web-accessible directories. This can potentially enable remote code execution through malicious webshell uploads, presenting significant risks to system integrity and data confidentiality.

Affected Version(s)

IoTSharp 0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alibek Baxtiyorov
.