CVE-2026-48099
HIGH
NVD
CVSS Score
7.1
Severity
HIGH
Published
Aug 13, 2026
Vendor
unknown
Description
WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4.