cvesecurityvulnerability
CVE-2026-13716: Path Traversal in Crafty Controller Enables Remote Code Execution
Critical path traversal (CVSS 9.1) in Crafty Controller's server import and admin file upload lets a remote authenticated attacker write files to arbitrary paths and achieve remote code execution. No fix available yet.