CVE-2026-70383: Arbitrary file overwrite vulnerability in DigiDoc4 client
Published Aug 20, 2026
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client.
This issue affects DigiDoc4: from 4.0.0 before 4.11.0.
Affected Software
1 affected component
Estonian Information System Authority (RIA) DigiDoc4 client>4.0.0<4.11.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DigiDoc4 clientto a version that resolves this vulnerability.Fixed in 4.11.0
Event History
Aug 20, 2026
CVE Published
via MITRE·02:04 PM
Data Sourced
via MITRE·02:04 PM
DescriptionWeakness
Frequently Asked Questions
1
Which DigiDoc4 versions are affected?
DigiDoc4 versions from 4.0.0 through versions before 4.11.0 are affected. Version 4.11.0 is not listed as affected.
2
What is the impact of successful exploitation?
Successful exploitation can allow arbitrary file overwrite through path traversal.