CVE-2026-0963Disclosure(craftycontrol / crafty_controller)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch craftycontrol crafty_controller systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crafty_controller

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 5 mentions (2026-01-30); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Products
crafty_controller

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-01-30: 5Mentions · 2026-01-31: 1Patch / Workaround · 2026-01-31: 1Technical Details · 2026-01-30: 5Technical Details · 2026-01-31: 101-3001-31
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-01-305
Disclosure5
2026-01-311
Patch1
Full discourse6 posts
  • PulsePatch.io@pulsepatchio
    Patch

    A path traversal vulnerability (CVE-2026-0963) affects Crafty Controller Crafty-4. This could lead to unauthorized file access. Review patch details. #infosec #pathtraversal #CraftyController https://www.pulsepatch.io/posts/cve-2026-0963-crafty-controller-crafty-4-path-traversal

    Post summary

    A path traversal issue (CVE‑2026‑0963) in Crafty Controller Crafty‑4 could enable unauthorized file access; a patch is available to mitigate it.

    0000064
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0963 Crafty Controller File Operations API Endpoint Path Traversal Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0963

    Post summary

    The message announces CVE-2026-0963, a path traversal flaw affecting the Crafty Controller File Operations API.

    0000092
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-0963: CRITICAL] Crafty Controller's File Operations API Endpoint component has an input neutralization vulnerability, enabling attackers to conduct file tampering and remote code execution. #cybersec...#cve,CVE-2026-0963,#cybersecurity https://cvefind.com/CVE-2026-0963

    Post summary

    The tweet announces a critical vulnerability in Crafty Controller’s File Operations API, highlighting an input neutralization flaw that enables file tampering and remote code execution, but it does not provide PoC, exploit code, or remediation details.

    0000074
    584 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-0963 - Critical An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code e... https://www.thehackerwire.com/vulnerability/CVE-2026-0963/ https://t.co/ZNnG84LT25

    Post summary

    CVE-2026-0963 is a critical input‑neutralization vulnerability in Crafty Controller’s File Operations API that permits authenticated remote attackers to tamper with files and run arbitrary code. No PoC, exploit, or patch is mentioned in the text.

    0000065
    113 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0963 An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tamperi… https://www.cve.org/CVERecord?id=CVE-2026-0963

    Post summary

    The post briefly reports a newly disclosed input neutralization flaw in Crafty Controller’s File Operations API that could allow authenticated users to tamper with files.

    00000246
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-0963: Improper Limitation of a Pathname... Authenticated path traversal in Crafty Controller's File Ops API enables trivial file manipulation and RCE - perfect for... https://zerodaysignal.com/vulnerability/CVE-2026-0963 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The message announces CVE-2026-0963, describing an authenticated path traversal flaw in Crafty Controller’s File Ops API that allows file manipulation and remote code execution, with further details likely available at the linked page.

    0000074
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcraftycontrolcrafty_controller4.7.0--

Explore more