216.73.216.197

CVE-2026-34027

· Published 15/06/2026 14:16 · Modified 15/06/2026 21:05 · Author: The MITRE Corporation

Labels: CVE-2026-34027 2026-06-15551230f0-3615-47bd-b7cc-93e92e730bbfCVE-2026-34027CWE-434

Essential information

Published
15/06/2026 14:16
Modified
15/06/2026 21:05
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
5.3 MEDIUM (v3) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CWE-434
CVSS vector

CVSS metrics

Description

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type validation in the /safe/contract/uploadcustomdocuments endpoint. The application validates uploaded files based on the user-controlled HTTP Content-Type value and accepts the upload if this value contains an allowed string such as pdf, jpeg, tiff, or png. An authenticated attacker with any role or permission level can spoof the Content-Type value and upload arbitrary file content.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
551230f0-3615-47bd-b7cc-93e92e730bbf
NVD
View on NVD

Affected products (CPE)

ProductCPE
wertheim / safecontroller cpe:2.3:a:wertheim:safecontroller:6.15.8328.28014:*:*:*:*:*:*:*

References