PT-2026-49822 · Serverco+1 · Getssl

·

CVE-2026-10303

·

Published

2026-06-16

·

Updated

2026-06-17

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ServerCo getssl versions prior to 2.49
Description Insufficient validation of the ACME challenge token against RFC 8555 during challenge-file handling allows a maliciously crafted token to influence local path or filename usage. An attacker capable of supplying ACME challenge responses—such as through a compromised CA endpoint or by tampering with the response path—can achieve unauthorized file write and path traversal effects. This typically occurs with elevated privileges and can lead to remote command injection. This is an instance of External Control of File Name or Path, where an external input determines the path used by the application.
Recommendations Update ServerCo getssl to a version newer than 2.49.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10303

Affected Products

Getssl