SEPTEMBER 25, 2026
Live Feed
Back to database
Case File

CVE-2026-34027

UNKNOWN · CVSS N/A EPSS 0.30%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-06-15 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. Exploitation may require the attacker to be authenticated.

CVE
CVE-2026-34027
Severity
UNKNOWN
CVSS
N/A
EPSS
0.30%

Original NVD Description

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type validation in the /safe/contract/uploadcustomdocuments endpoint. The application validates uploaded files based on the user-controlled HTTP Content-Type value and accepts the upload if this value contains an allowed string such as pdf, jpeg, tiff, or png. An authenticated attacker with any role or permission level can spoof the Content-Type value and upload arbitrary file content.