Path-traversal
3 posts tagged with “Path-traversal”

CVE-2026-33922: Nozomi Arc Path Traversal Lets Admins Delete Arbitrary Files on OT Security Appliances
A path traversal vulnerability in Nozomi Arc before v2.7.0 lets local web interface administrators delete arbitrary files by submitting crafted archive names in the Offline archives feature. Fixed in version 2.7.0.

CVE-2026-13716: Path Traversal in Crafty Controller Enables Remote Code Execution
Critical path traversal (CVSS 9.1) in Crafty Controller's server import and admin file upload lets a remote authenticated attacker write files to arbitrary paths and achieve remote code execution. No fix available yet.

CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files
Hugging Face Accelerate through 1.14.0 fails to sanitize weight_map entries in sharded checkpoint indexes, allowing arbitrary file reads and denial of service via named pipes. Affects 27M monthly downloads.