Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 4.10.8
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arcadia Technology
Arcadia Technology crafty Controller |
|
| Vendors & Products |
Arcadia Technology
Arcadia Technology crafty Controller |
Tue, 11 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution. | |
| Title | Path Traversal: '.../...//' in Crafty Controller | |
| Weaknesses | CWE-35 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-08-11T16:58:17.980Z
Reserved: 2026-06-29T14:04:39.352Z
Link: CVE-2026-13716
Updated: 2026-08-11T16:58:12.611Z
Status : Received
Published: 2026-08-11T06:17:12.870
Modified: 2026-08-11T17:17:47.430
Link: CVE-2026-13716
No data.
OpenCVE Enrichment
Updated: 2026-08-11T07:30:03Z