Unrated severityNVD Advisory· Published Jul 13, 2026· Updated Jul 16, 2026
Arbitrary file overwrite through certificate update functionality
CVE-2026-22102
Description
A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in the Content-Disposition header without verification. This can be used to cause a denial of service by overwriting system files, or remote-code-execution by overwriting shell-scripts which execution can be triggered through other means.
Patches
Vulnerability mechanics
References
1- csirt.divd.nl/DIVD-2026-00001/mitrethird-party-advisory
News mentions
0No linked articles in our index yet.