CVE-2026-22102
Arbitrary file overwrite through certificate update functionality
| CVE | CVE-2026-22102 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Title | Arbitrary file overwrite through certificate update functionality | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Credits |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Affected products |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| CVSS |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| References |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Problem type(s) | CWE-20 Improper Input Validation | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Date published | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Last modified | 16 Jul 2026 15:41 UTC | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in the Content-Disposition header without verification.
This can be used to cause a denial of service by overwriting system files, or remote-code-execution by overwriting shell-scripts which execution can be triggered through other means.
This can be used to cause a denial of service by overwriting system files, or remote-code-execution by overwriting shell-scripts which execution can be triggered through other means.
JSON version.