← Back to browse · API

CVE-2026-0963

Severity
CRITICAL
CVSS
9.9
EPSS
0.00681
Risk score
39.84
CISA KEV
No
PoC
No
Published
2026-01-30
Modified
2026-02-02
First seen
2026-08-07
Aliases
EUVD-2026-5044, GHSA-8PHM-9C2M-9HPQ
Products
Arcadia Technology, LLC:Crafty Controller 4.7.0 <4.8.0
Sources
euvd EUVD-2026-5044

Description

An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.

References