Security Risk Category

Arbitrary File Write Security Risks — Page 2

Published vulnerability pages connected to Arbitrary File Write. Each page keeps one canonical URL and focused remediation guidance.

116 published Arbitrary File Write risks

Arbitrary File Write risks

Showing 37–72 of 116 published risks.

criticalEPSS 0.010

CVE-2026-58126 in PACSgear PACS Scan

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication requirement. Attackers can chain the arbitrary file write primitive with DLL hijacking in PGImageExchangeQueueSvc.exe, which loads missing DLLs such as CRYPTSP.DLL from the application directory, to achieve remote code execution as NT Authority\SYSTEM upon service restart.

CVE-2026-58126dotnetwindowsnetwork-securityremote-code-execution

Updated Jul 15, 2026

criticalEPSS 0.010

CVE-2026-58127 in PACSgear MediaWriter

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObject object unmarshalling technique and implementing .NET WebClient class methods, an unauthenticated remote attacker can read and write arbitrary files on the host filesystem. The ObjectURIs are identical across all installations by default. Chaining the arbitrary file write primitive with DLL hijacking opportunities in the MediaWriter service (which runs as NT Authority\\SYSTEM and loads missing DLLs such as CRYPTBASE.DLL from the application directory) enables unauthenticated remote code execution as SYSTEM upon service restart.

CVE-2026-58127dotnetwindowsnetwork-securityremote-code-execution

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-57830 in Helix Ultimate for Joomla

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

CVE-2026-57830joomlaauthorization-bypassfile-writefile-deletion

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-14906 in Firefox for iOS

Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4.

CVE-2026-14906browserinput-validationfile-uploadfile-write

Updated Jul 15, 2026

mediumEPSS 0.001

CVE-2026-15681 in AnyDesk

AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of screen recording files. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26591.

CVE-2026-15681denial-of-servicepath-traversalfile-write

Updated Jul 15, 2026

mediumEPSS 0.001

CVE-2026-15682 in AnyDesk

AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Send Support Information feature. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26645.

CVE-2026-15682denial-of-servicepath-traversalfile-write

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62189 in OpenClaw

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization boundaries when the feature is enabled and reachable.

CVE-2026-62189npmauthorization-bypasspath-traversalfile-write

Updated Jul 15, 2026

medium

CVE-2026-49488 in Apache OpenMeetings

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS account running the OM server, including credentials and secrets, via a crafted download request. Users are recommended to upgrade to version 9.1.0, which fixes the issue.

CVE-2026-49488javaweb-applicationinformation-disclosurepath-traversal

Updated Jul 15, 2026

medium

CVE-2026-11944 in openSIS Classic

openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences.

CVE-2026-11944web-applicationinformation-disclosurepath-traversalfile-write

Updated Jul 15, 2026

critical

CVE-2026-13001 in Podlove Podcast Publisher

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2026-13001wordpressremote-code-executioninput-validationfile-upload

Updated Jul 15, 2026

highEPSS 0.001

CVE-2026-41121 in Dell Device Management Agent

Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Link Following’) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

CVE-2026-41121windowspath-traversalfile-writeprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.007

CVE-2026-49119 in Gradio

Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory traversal sequences or absolute paths. Attackers can provide crafted path segments that cause os.path.join to discard the root_dir prefix entirely, resulting in arbitrary file read or exposure of sensitive files outside the intended directory.

CVE-2026-49119pythonweb-applicationinformation-disclosurepath-traversal

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-53489 in containerd

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.

CVE-2026-53489cloud-securitydevopsinformation-disclosurepath-traversal

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-54406 in UniFi Network Application

A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.

CVE-2026-54406network-securitypath-traversalfile-writeprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.005

CVE-2026-44941 in libzypp

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.

CVE-2026-44941linuxsupply-chainpath-traversalfile-write

Updated Jul 14, 2026

lowEPSS 0.003

CVE-2026-53422 in Erlang/OTP SSH

Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of files and directories outside the configured root directory. The SSH_FXP_REALPATH handler in ssh_sftpd calls relate_file_name/3 with Canonicalize=false, unlike every other SFTP operation handler. This allows .. components in the requested path to bypass the is_within_root/2 check without being resolved. The un-canonicalized path then enters resolve_symlinks/2, which walks up the directory tree above the configured root and issues read_link() syscalls on arbitrary filesystem paths. An authenticated SFTP client can exploit this by sending a REALPATH request with a crafted traversal path. The server response differs depending on whether the target path exists on the host filesystem (SSH_FXP_NAME when the path resolves successfully, SSH_FX_NO_SUCH_FILE when it does not). This creates a path-existence oracle that an attacker can use to enumerate the filesystem structure outside the configured root, including the existence of sensitive files, directories, and mount points. The vulnerability leaks only the existence of paths. No file contents, credentials, or write access are obtainable through this issue alone. The information gained may assist further attacks when combined with other vulnerabilities. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and program routine ssh_sftpd:handle_op/4. This issue affects OTP from OTP 17.0 until OTP 29.0.3, 28.5.0.3, and 27.3.4.14 corresponding to ssh from 3.0.1 until 6.0.2, 5.5.2.2, and 5.2.11.9.

CVE-2026-53422network-securityinformation-disclosurepath-traversalfile-write

Updated Jul 14, 2026

high

CVE-2026-13054 WatchGuard Fireware Vulnerability

A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.

CVE-2026-13054network-securitypath-traversalfile-write

Updated Jul 14, 2026

criticalEPSS 0.005

CVE-2026-24014 iotdb vulnerability

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory. This could allow arbitrary file write with the permissions of the IoTDB process. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.

CVE-2026-24014authorization-bypasspath-traversalfile-uploadfile-write

Updated Jul 13, 2026

highEPSS 0.011

CVE-2026-49297 apache-airflow-providers-google vulnerability

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the source GCS bucket (typically a different trust principal than the DAG author — partner uploads, ingest-only service accounts, public-data buckets) could create an object whose name contains `..` segments and cause the DAG run to write the downloaded blob outside the configured destination (the SFTP `destination_path` for `GCSToSFTPOperator`; the worker-local temp directory for `GCSTimeSpanFileTransformOperator`), enabling overwrite of arbitrary files on the SFTP server or the worker host. Affects deployments that ingest from buckets writable by less-trusted principals. Users are advised to upgrade to `apache-airflow-providers-google` 22.2.1 or later.

CVE-2026-49297network-securityapi-securitydevopspath-traversal

Updated Jul 13, 2026

criticalEPSS 0.004

CVE-2026-9182 arcgis server vulnerability

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.

CVE-2026-9182linuxwindowscloud-securityweb-application

Updated Jul 13, 2026

mediumEPSS 0.003

CVE-2026-58403 hugo vulnerability

Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files under a mount cannot reach outside the mount tree, but a regression caused RootMappingFs.statRoot to call Stat, which follows symlinks, instead of Lstat, so a direct os.ReadFile "somefile" where somefile was a symlink pointing outside the mount would return the target's contents. This effectively let a symlink planted inside a theme or local mount read arbitrary files reachable to the user running hugo. This issue is fixed in v0.163.1.

CVE-2026-58403path-traversalfile-write

Updated Jul 13, 2026

mediumEPSS 0.003

CVE-2026-50135 hugo vulnerability

Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows symlinks) instead of Lstat , so a direct resources.Get of a symlink pointing outside its mount returned the target's contents — letting a symlink planted in a local mount (e.g. a vendored themes/ theme) read arbitrary files accessible to the Hugo user. Go-module themes from GitHub (symlinks stripped) and directory walks were unaffected. Fixed in 0.162.0.

CVE-2026-50135path-traversalfile-write

Updated Jul 13, 2026

criticalEPSS 0.005

CVE-2026-57571 crawl4ai vulnerability

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. A filename containing an absolute path or traversal escaped the downloads directory, giving an arbitrary file write with attacker-controlled contents; the HTTP crawler path uses the response Content-Disposition filename and the browser crawler path uses the download's suggested filename. Because the written bytes are attacker-controlled, this can escalate to remote code execution. This issue is fixed in version 0.9.0.

CVE-2026-57571browserremote-code-executionpath-traversalfile-write

Updated Jul 13, 2026

mediumEPSS 0.003

CVE-2026-39245 decompress vulnerability

decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDir function (index.js line 29) and the extraction path validation (index.js line 106) use String.indexOf() to verify the resolved path is within the output directory: realDestinationDir.indexOf(realOutputPath) !== 0. This check is flawed because it does not enforce a path separator boundary. For example, "/tmp/app_config".indexOf("/tmp/app") returns 0, incorrectly passing the check even though /tmp/app_config is outside /tmp/app. Combined with the unvalidated symlink creation in the same package, an attacker can write arbitrary files to directories adjacent to the extraction target. This is a bypass of the fix for CVE-2020-12265. The correct check requires appending a path separator: realParentPath.indexOf(realOutputPath + path.sep) !== 0.

CVE-2026-39245path-traversalfile-write

Updated Jul 13, 2026

highEPSS 0.005

TheGem Theme Elements <= 5.11.1 - Authenticated (Contributor+) Local File Inclusion

The TheGem Theme Elements plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.11.1. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

CVE-2026-57804wordpressphpauthorization-bypasspath-traversal

Updated Jul 13, 2026

highEPSS 0.005

Billey <= 2.1.8 - Authenticated (Contributor+) Local File Inclusion

The Billey theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.8. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

CVE-2026-57790wordpressphpauthorization-bypasspath-traversal

Updated Jul 13, 2026

highEPSS 0.005

AR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File Read via 'file' Parameter

The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The three intended access controls all fail: valid nonces are freely minted by unauthenticated callers via the nopriv ar_get_fresh_nonce and ar_process_user_image AJAX handlers; the AES-256-CBC encryption key is derived from get_option('ar_licence_key'), which returns false on default free installations and yields a predictable key attackers can use to encrypt their own path payloads; and the Referer check is trivially bypassed because the Referer header is attacker-controlled.

CVE-2026-14352wordpresswoocommerceauthorization-bypassinformation-disclosure

Updated Jul 13, 2026

highEPSS 0.008

Perfmatters <= 2.6.4 - Unauthenticated Arbitrary File Read via 's' Parameter

The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 via the 's' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the Local Google Fonts feature to be enabled (disabled by default), pretty permalinks to be active, and RSS feed links to remain enabled in the plugin settings.

CVE-2026-13251wordpressinformation-disclosurepath-traversalfile-write

Updated Jul 13, 2026

mediumEPSS 0.004

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, and including, 1.5.1. The function reads raw_value from Elementor Pro's Form_Record object for upload-type fields and passes it directly to PHP's copy() without validating that the value corresponds to a legitimately uploaded file — when no file is present in $_FILES, raw_value reflects the attacker-controlled POST string. copy() accepts both local filesystem paths and URL sources, so the attacker can target any file readable by the PHP process or supply an attacker-controlled remote URL. Elementor Pro is a prerequisite for triggering the code path (it owns the elementor_pro/forms/new_record hook and populates the Form_Record object), but the bug itself is entirely in Contact Form Entries' handler. This could allow unauthenticated attackers to disclose arbitrary files on the affected site's server. The file is copied to a directory unknown to the attacker; the hashed directory name provides defense-in-depth but is generated from non-cryptographic sources (uniqid() + rand()) and should not be relied upon as the primary mitigation.

CVE-2026-9145wordpressphppath-traversalfile-write

Updated Jul 13, 2026

highEPSS 0.005

Brook - Agency Business Creative WordPress Theme <= 2.9.0 - Authenticated (Contributor+) Local File Inclusion

The Brook - Agency Business Creative WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.9.0. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

CVE-2026-57791wordpressphpauthorization-bypasspath-traversal

Updated Jul 13, 2026

highEPSS 0.005

Golo Framework <= 1.7.3 - Authenticated (Contributor+) Local File Inclusion

The Golo Framework plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.3. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

CVE-2026-57794wordpressphpauthorization-bypasspath-traversal

Updated Jul 13, 2026

highEPSS 0.003

SportsPress Pro <= 2.7.29 - Authenticated (Contributor+) Local File Inclusion

The SportsPress Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7.29. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

CVE-2026-57749wordpressphpauthorization-bypasspath-traversal

Updated Jul 13, 2026

criticalEPSS 0.007

Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 - Unauthenticated Arbitrary File Deletion

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key' POST parameter sanitized only with sanitize_text_field() — which does not strip path traversal sequences — and then passes that path directly to Nbdesigner_IO::delete_folder() and PHP's rename(). The nonce protecting the nbd_save_customer_design AJAX action is freely obtainable by unauthenticated users via the nbd_check_use_logged_in endpoint. This makes it possible for unauthenticated attackers to delete arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2026-9725wordpresswoocommercephpremote-code-execution

Updated Jul 13, 2026

highEPSS 0.005

Leedo <= 3.0.0 - Authenticated (Contributor+) Local File Inclusion

The Leedo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

CVE-2026-57796wordpressphpauthorization-bypasspath-traversal

Updated Jul 13, 2026

highEPSS 0.003

Shopify <= 1.0.0 - Authenticated (Contributor+) Local File Inclusion

The Shopify plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.0. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

CVE-2026-57748wordpressphpauthorization-bypasspath-traversal

Updated Jul 13, 2026

highEPSS 0.005

Flow <= 1.8 - Authenticated (Contributor+) Local File Inclusion

The Flow theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

CVE-2026-57793wordpressphpauthorization-bypasspath-traversal

Updated Jul 13, 2026