PT-2026-79021 · Digidoc4 · Digidoc4

CVE-2026-70383

·

Published

2026-08-20

·

Updated

2026-08-20

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions DigiDoc4 versions 4.0.0 through 4.10.9
Description The DigiDoc4 client contains a path traversal issue, which occurs when an application uses user-supplied input to construct a pathname that is intended to be restricted to a specific directory, but fails to properly limit it. This can lead to an arbitrary file overwrite.
Recommendations Update DigiDoc4 to version 4.11.0 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70383

Affected Products

Digidoc4