PT-2026-49201 · Wertheim · Safecontroller

CVE-2026-34030

·

Published

2026-06-15

·

Updated

2026-06-15

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Wertheim SafeController Software version 6.15.8328.28014
Description Insufficient validation of the branch code during the creation of a new branch allows an authenticated attacker with the settings branches manage privilege to perform path traversal. The branch code is utilized in various application functions to generate filesystem paths for settings, profile pictures, and uploaded files. By including path traversal sequences—characters used to navigate through the directory structure—in the branch code, an attacker can influence the final filesystem location of file operations, potentially storing files in unintended directories based on service-account write permissions and length restrictions.
Recommendations Update Wertheim SafeController Software to a version that properly validates branch code during creation. As a temporary mitigation, restrict the settings branches manage privilege to only highly trusted administrators.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34030

Affected Products

Safecontroller