
🚨Critical - IoTSharp BlobStorageController Unauth Path Traversal to File Write/RCE (CVE-2026-71262) IoTSharp BlobStorageController endpoints Upload/Download/List/Modify/Delete are exposed without auth due to missing authorization config. Unsanitized path/filename enables ../ traversal to read/write/modify/delete arbitrary files outside the blob dir, leading to RCE by planting a webshell in a web-accessible path. 👉Affected: IoTSharp (versions unknown)
Post summary
The post announces a critical uncontrolled path traversal vulnerability in IoTSharp’s BlobStorageController, enabling unauthenticated file writes and remote code execution through webshell deployment.
