Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 10 Aug 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fledge's backup-restore upload handler, upload_backup() (python/fledge/services/core/api/backup_restore.py), calls tarfile.extractall(temp_path) on an admin-uploaded tar archive with no filter argument and no per-member path validation. A crafted tar archive containing member names with `../` path components extracts files outside the intended temporary directory, allowing arbitrary file writes anywhere on the filesystem reachable by the Fledge process. Requires the admin role (@has_permission("admin")). | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile.extractall(temp_path) on an admin-uploaded tar archive with no filter argument and no per-member path validation. Requires the admin role (@has_permission("admin")). |
| Title | Fledge IoT Gateway - Backup Restore Tar Path Traversal | Fledge IoT Gateway Backup Restore Tar Path Traversal |
Mon, 10 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Fledge IoT Gateway Backup Restore Tar Path Traversal | Fledge IoT Gateway - Backup Restore Tar Path Traversal |
Fri, 07 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fledge-iot
Fledge-iot fledge |
|
| Vendors & Products |
Fledge-iot
Fledge-iot fledge |
Wed, 05 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Aug 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fledge's backup-restore upload handler, upload_backup() (python/fledge/services/core/api/backup_restore.py), calls tarfile.extractall(temp_path) on an admin-uploaded tar archive with no filter argument and no per-member path validation. A crafted tar archive containing member names with `../` path components extracts files outside the intended temporary directory, allowing arbitrary file writes anywhere on the filesystem reachable by the Fledge process. Requires the admin role (@has_permission("admin")). | |
| Title | Fledge IoT Gateway Backup Restore Tar Path Traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-10T11:47:08.697Z
Reserved: 2026-08-05T12:23:34.968Z
Link: CVE-2026-71283
Updated: 2026-08-05T15:52:59.221Z
Status : Received
Published: 2026-08-05T13:24:52.970
Modified: 2026-08-10T12:17:30.903
Link: CVE-2026-71283
No data.
OpenCVE Enrichment
Updated: 2026-08-10T21:00:04Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')