Unauthorized Access Vulnerability in IoTSharp's Blob Storage Controller
CVE-2026-71262
9.8CRITICAL
What is CVE-2026-71262?
The BlobStorageController in IoTSharp lacks proper authorization controls, exposing critical upload, download, modification, and deletion endpoints to unauthorized access. Without an [Authorize] attribute and missing global authorization policies, these endpoints can be exploited by remote attackers. The absence of sanitization for path and filename parameters creates a pathway for path traversal vulnerabilities, allowing attackers to not only manipulate files within the intended storage but also reach web-accessible directories. This can potentially enable remote code execution through malicious webshell uploads, presenting significant risks to system integrity and data confidentiality.
Affected Version(s)
IoTSharp 0
