AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-48099

HIGH · CVSS 7.1 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

WsgiDAV versions 4.3.3 and earlier are vulnerable to a directory traversal attack that allows an attacker to craft a WebDAV request capable of escaping the configured filesystem share root, potentially exposing sensitive files. This vulnerability poses a high risk, particularly for organizations using WsgiDAV for file sharing and collaboration. Users of affected versions should prioritize upgrading to version 4.3.4 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-48099
Severity
HIGH
CVSS
7.1
EPSS
0.33%

Original NVD Description

WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4.