High severity8.2OSV Advisory· Published Jan 30, 2026· Updated Jun 17, 2026
CVE-2026-0805
CVE-2026-0805
Description
An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.
Affected products
3- cpe:2.3:a:craftycontrol:crafty_controller:*:*:*:*:*:*:*:*Range: >=4.5.0,<4.8.0
v4.5.0, v4.5.1, v4.5.2, …+ 1 more
- (no CPE)range: v4.5.0, v4.5.1, v4.5.2, …
- (no CPE)
Patches
Vulnerability mechanics
References
1- gitlab.com/crafty-controller/crafty-4/-/issues/650nvdBroken Link
News mentions
0No linked articles in our index yet.