PT-2026-49201 · Wertheim · Safecontroller
CVE-2026-34030
·
Published
2026-06-15
·
Updated
2026-06-15
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Wertheim SafeController Software version 6.15.8328.28014
Description
Insufficient validation of the branch code during the creation of a new branch allows an authenticated attacker with the
settings branches manage privilege to perform path traversal. The branch code is utilized in various application functions to generate filesystem paths for settings, profile pictures, and uploaded files. By including path traversal sequences—characters used to navigate through the directory structure—in the branch code, an attacker can influence the final filesystem location of file operations, potentially storing files in unintended directories based on service-account write permissions and length restrictions.Recommendations
Update Wertheim SafeController Software to a version that properly validates branch code during creation. As a temporary mitigation, restrict the
settings branches manage privilege to only highly trusted administrators.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Safecontroller