CVE-2026-0805Disclosure(craftycontrol / crafty_controller)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch craftycontrol crafty_controller systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crafty_controller

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-01-30); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
crafty_controller

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-01-30: 3Mentions · 2026-01-31: 1PoC Mentioned / Linked · 2026-01-30: 1Patch / Workaround · 2026-01-31: 1Technical Details · 2026-01-30: 3Technical Details · 2026-01-31: 101-3001-31
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-303
Disclosure2General1
2026-01-311
Patch1
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Patch

    Crafty Controller has a path traversal flaw (CVE-2026-0805). This could allow unauthorized file access. Review and patch your systems. #infosec #vulnerability #security https://www.pulsepatch.io/posts/cve-2026-0805-crafty-controller-path-traversal

    Post summary

    The post identifies a path traversal vulnerability (CVE‑2026‑0805) in Crafty Controller that allows unauthorized file access and urges users to review and apply patches.

    00000161
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0805 Crafty Controller Path Traversal Vulnerability Enables Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0805

    Post summary

    CVE-2026-0805 is a disclosed path‑traversal flaw in Crafty Controller that allows remote code execution.

    0000099
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-0805 - High An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via... https://www.thehackerwire.com/vulnerability/CVE-2026-0805/ https://t.co/KWpRuOUoiT

    Post summary

    CVE-2026-0805 is an input neutralization flaw in Crafty Controller’s Backup Configuration component that permits authenticated attackers to tamper with files and execute remote code; the tweet links to an advisory but provides no exploit tool or patch information.

    0000076
    113 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-0805 An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and r… https://www.cve.org/CVERecord?id=CVE-2026-0805

    Post summary

    The post announces CVE‑2026‑0805, describing an input neutralization flaw in Crafty Controller that enables file tampering, but it provides none of the other typical indicators such as PoC, exploit code, active exploitation, or patch information.

    00000267
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcraftycontrolcrafty_controller---

Explore more