CVE-2026-13716: Path Traversal: '.../...//' in Crafty Controller
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Crafty Controllerto a version that resolves this vulnerability.Fixed in 4.10.8