Threats Tagged 'cve-2026-71262'
View all threats tagged with 'cve-2026-71262'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-71262'
Click on any threat for detailed analysis and mitigation recommendations
IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController,… (CVE-2026-71262)CVE-2026-71262 0 IoTSharp's BlobStorageController.cs lacks the [Authorize] attribute that is applied to other controllers, and no global authorization fallback policy is configured. This allows unauthenticated remote attackers to access Upload, Download, List, Modify, and Delete endpoints. The endpoints accept path and filename parameters without sanitization, enabling path traversal attacks that can read, write, modify, or delete arbitrary files outside the intended blob storage directory. This includes web-accessible paths, which can be exploited for remote code execution via webshell upload. The vulnerability has a critical CVSS score of 9.8. Join the discussion | GCVE Database | 08/05/2026, 15:32:19 UTC Added: 08/05/2026, 18:47:03 UTC |
Showing 1 to 1 of 1 result