Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client.

This issue affects DigiDoc4: from 4.0.0 before 4.11.0.
Published: 2026-08-20
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The DigiDoc4 client contains a Path Traversal flaw that enables an attacker to overwrite files outside the intended directory. This issue can lead to the replacement of critical system or application files, potentially allowing further exploitation or denial of service. The weakness is identified as CWE-22 and is rated with a CVSS score of 8.4, indicating a high severity impact if exploited.

Affected Systems

The vulnerability is present in DigiDoc4 versions 4.0.0 through 4.10.x, all releases before 4.11.0, issued by the Estonian Information System Authority (RIA). Only these specific version ranges are affected; newer versions are presumed fixed.

Risk and Exploitability

With an unavailable EPSS score, the likelihood of exploitation is unclear, yet the high CVSS suggests significant risk. The CVE is not listed in the CISA KEV catalog. The path traversal flaw would likely be exploited by a local user or a malicious document that forces the client to write arbitrary data to a chosen location. No public exploit code is cited, but the high severity warrants immediate attention.

Generated by OpenCVE AI on August 20, 2026 at 21:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade DigiDoc4 to version 4.11.0 or later where the bug is fixed
  • If an update is not possible, configure the client to restrict writable directories and ensure no write permissions are granted to untrusted locations
  • Apply operating‑system level file‑system permissions or host‑based firewalls to prevent the client from writing to critical system paths

Generated by OpenCVE AI on August 20, 2026 at 21:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Estonian Information System Authority (ria)
Estonian Information System Authority (ria) digidoc4
Vendors & Products Estonian Information System Authority (ria)
Estonian Information System Authority (ria) digidoc4

Thu, 20 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client. This issue affects DigiDoc4: from 4.0.0 before 4.11.0.
Title Arbitrary file overwrite vulnerability in DigiDoc4 client
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Estonian Information System Authority (ria) Digidoc4
cve-icon MITRE

Status: PUBLISHED

Assigner: ENISA

Published:

Updated: 2026-08-20T14:04:15.480Z

Reserved: 2026-08-04T07:41:00.082Z

Link: CVE-2026-70383

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T14:17:58.050

Modified: 2026-08-20T14:17:58.050

Link: CVE-2026-70383

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T21:15:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')