Arbitrary File Write Vulnerability in Fledge Backup Restore Functionality
CVE-2026-71283
4.9MEDIUM
What is CVE-2026-71283?
The backup and restore functionality of Fledge is susceptible to an arbitrary file write vulnerability due to improper handling of tar archive uploads. Specifically, the upload_backup() method allows admin users to upload tar files without validating member paths. This can enable malicious users with admin permissions to craft tar files that leverage ../ components, facilitating the extraction of files to unintended directories on the system, leading to potential security breaches and unauthorized access to sensitive data.
Affected Version(s)
fledge 0 <= 3.1.0
