OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-103398

HIGH · CVSS 8.1 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

OpenSave versions up to 2.4.0 are vulnerable due to improper validation of save paths, allowing attackers to manipulate file directories beyond the intended save locations. This flaw enables unauthorized reading and writing of files through manifest and sync routes, posing a significant risk to data integrity and confidentiality. Organizations utilizing OpenSave should prioritize remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103398
Severity
HIGH
CVSS
8.1
EPSS
0.27%

Original NVD Description

OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes.