PT-2026-40443 · Efw · Efw

CVE-2026-44257

·

Published

2026-05-12

·

Updated

2026-05-13

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions efw4.X versions prior to 4.08.010
Description The unZip function in efw.file.FileManager writes zip entries to disk using new File(baseDir, zipEntry.getName()) without performing a canonical-path check. This allows an attacker to use entry names containing path traversal sequences, such as ../../../pwned.jsp, to escape the intended extraction directory and write files to any location accessible by the Tomcat process, including the servlet context root. When combined with the /uploadServlet multipart endpoint and an event that triggers file.saveUploadFiles and FileManager.unZip, an unauthenticated remote attacker can upload a JSP webshell to execute arbitrary commands with the privileges of the Tomcat user.
Recommendations Update to version 4.08.010.

Exploit

Fix

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44257
GHSA-Q7JX-7X5R-R9F6

Affected Products

Efw