CVE-2026-71283: CWE-22 in fledge-iot fledge
Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile.extractall(temp_path) on an admin-uploaded tar archive with no filter argument and no per-member path validation. Requires the admin role (@has_permission("admin")).
AI Analysis
Technical Summary
The vulnerability in fledge-iot's fledge occurs in the upload_backup function located in python/fledge/services/core/api/backup_restore.py. This function uses tarfile.extractall(temp_path) to extract tar archives uploaded by users with admin permissions. Because the extraction is done without filtering or validating the paths of the archive members, it is vulnerable to directory traversal attacks (CWE-22). An attacker with admin role can craft a malicious tar archive that, when extracted, writes files outside the intended directory, potentially overwriting critical files or injecting malicious content.
Potential Impact
An attacker with administrative privileges can exploit this vulnerability to overwrite arbitrary files on the system by uploading a specially crafted tar archive. This could lead to integrity violations of the system or application files. There is no direct confidentiality or availability impact indicated. Exploitation requires admin-level permissions, limiting the attack surface.
Mitigation Recommendations
No official patch or remediation has been published yet. Since the vulnerability requires admin privileges, restrict admin access to trusted users only. Monitor vendor advisories for an official fix or update. Implementing path validation and filtering when extracting tar archives is recommended once a fix is available.
CVE-2026-71283: CWE-22 in fledge-iot fledge
Description
Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile.extractall(temp_path) on an admin-uploaded tar archive with no filter argument and no per-member path validation. Requires the admin role (@has_permission("admin")).
CVSS v3.1
Score 4.9medium
Affected software
fledge-iot
fledge
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in fledge-iot's fledge occurs in the upload_backup function located in python/fledge/services/core/api/backup_restore.py. This function uses tarfile.extractall(temp_path) to extract tar archives uploaded by users with admin permissions. Because the extraction is done without filtering or validating the paths of the archive members, it is vulnerable to directory traversal attacks (CWE-22). An attacker with admin role can craft a malicious tar archive that, when extracted, writes files outside the intended directory, potentially overwriting critical files or injecting malicious content.
Potential Impact
An attacker with administrative privileges can exploit this vulnerability to overwrite arbitrary files on the system by uploading a specially crafted tar archive. This could lead to integrity violations of the system or application files. There is no direct confidentiality or availability impact indicated. Exploitation requires admin-level permissions, limiting the attack surface.
Mitigation Recommendations
No official patch or remediation has been published yet. Since the vulnerability requires admin privileges, restrict admin access to trusted users only. Monitor vendor advisories for an official fix or update. Implementing path validation and filtering when extracting tar archives is recommended once a fix is available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-08-05T12:23:34.968Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7336e7bf8831d539ed92e2
Added to database: 08/05/2026, 13:13:11 UTC
Last enriched: 08/12/2026, 14:34:55 UTC
Last updated: 09/18/2026, 02:25:16 UTC
Views: 50
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.