PT-2026-23044 · Elgato+1 · Elgato Stream Deck+1

Ambiso

·

Published

2026-03-04

·

Updated

2026-03-05

·

CVE-2026-28427

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenDeck versions prior to 2.8.1
Description OpenDeck is Linux software for the Elgato Stream Deck. The service listening on port 57118 serves static files for installed plugins without proper path sanitization. An attacker can use '../' sequences in the request path to traverse outside the intended directory and read arbitrary files accessible to OpenDeck. The vulnerable component serves static files for installed plugins.
Recommendations Update to OpenDeck version 2.8.1 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-28427
GHSA-4974-G27Q-H5M8

Affected Products

Elgato Stream Deck
Opendeck