Vulnerability Description
WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout. The issue is fixed with version 4.3.4.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/mar10/wsgidav/commit/f894ed8656d7bdd7438ab8148c5a02546cb15183
- https://github.com/mar10/wsgidav/security/advisories/GHSA-wxq4-cc2q-338q
- https://github.com/pypa/advisory-database/tree/main/vulns/wsgidav/PYSEC-2026-342
FAQ
What is CVE-2026-48099?
CVE-2026-48099 is a vulnerability with a CVSS score of 7.1 (HIGH). WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesys...
How severe is CVE-2026-48099?
CVE-2026-48099 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-48099?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.