PT-2026-49198 · Wertheim · Safecontroller

CVE-2026-34027

·

Published

2026-06-15

·

Updated

2026-06-15

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Wertheim SafeController Software version 6.15.8328.28014
Description Insufficient server-side file type validation exists in the '/safe/contract/uploadcustomdocuments' endpoint. The application relies on the user-controlled HTTP Content-Type value to validate uploaded files, accepting them if the value contains allowed strings such as pdf, jpeg, tiff, or png. An authenticated attacker with any role or permission level can spoof the Content-Type value to upload arbitrary file content.
Recommendations Update Wertheim SafeController Software version 6.15.8328.28014 to a version that implements strict server-side file validation. As a temporary workaround, restrict access to the '/safe/contract/uploadcustomdocuments' endpoint.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34027

Affected Products

Safecontroller