Description
An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.
Published: 2026-01-30
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade to version 4.8.0

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 26 Feb 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Craftycontrol
Craftycontrol crafty Controller
CPEs cpe:2.3:a:craftycontrol:crafty_controller:*:*:*:*:*:*:*:*
Vendors & Products Craftycontrol
Craftycontrol crafty Controller

Tue, 03 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Arcadia Technology
Arcadia Technology crafty Controller
Vendors & Products Arcadia Technology
Arcadia Technology crafty Controller

Mon, 02 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 30 Jan 2026 06:30:00 +0000

Type Values Removed Values Added
Description An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.
Title Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty Controller
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Arcadia Technology Crafty Controller
Craftycontrol Crafty Controller
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-02-02T16:33:11.255Z

Reserved: 2026-01-09T10:40:55.812Z

Link: CVE-2026-0805

cve-icon Vulnrichment

Updated: 2026-01-30T14:23:55.487Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-30T07:16:14.917

Modified: 2026-02-26T19:57:06.950

Link: CVE-2026-0805

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T01:15:05Z

Weaknesses