CVE-2026-14947CWE-24

CVE-2026-14947

High · published August 20, 2026

CVSS v3.1
7.2
EPSS
1%
Percentile
58.6
In the wild
Unconfirmed
What it is

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.

The record
Technical detail
CVSS v3.1
7.2 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
8.6 · CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00940 · 58.6th percentile
Weakness
CWE-24 · Path Traversal: '../filedir'
Published
2026-08-20T13:16Z
References (1)
EPSS history
Timeline
  • 20 AUG 08:18Z
    Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP file
    cvelistv5