CRITICAL
IoTSharp
CVE published 2026-08-05
CVE-2026-71262
The IoTSharp application has a critical vulnerability in its BlobStorageController.cs, which lacks the [Authorize] attribute, making its endpoints accessible to unauthenticated remote attackers. This vulnerability, combined with unsanitized path and filename parameters, allows for path traversal and potential remote code execution via webshell upload. The affected product is IoTSharp, and the vulnerabilit [truncated]