ZeroHour

Vulnerabilities

1 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-13716
Authenticated Path Traversal to RCE in Crafty Controller

Crafty Controller, an open-source web panel for managing game servers, contains a path-traversal flaw (CWE-35) in its server import and administrator file-upload features. An attacker holding valid, low-privilege authentication credentials can upload crafted files to arbitrary filesystem paths that the application is permitted to write. By placing attacker-controlled files in privileged locations, the attacker achieves remote code execution on the host running the panel, consistent with the changed-scope (S:C) component of the 9.1 CVSS score. The flaw affects Crafty Controller deployments; the published references point to the Crafty 4 (crafty-4) codebase, but no specific vulnerable version ranges were provided in the available data. There is currently no evidence of exploitation in the wild (not listed in CISA KEV, EPSS 0.7%), and two public PoC/tracker references exist, so defenders should treat this as a critical but not yet actively exploited issue.

Do: Upgrade Crafty Controller to the latest release as soon as the vendor's fix is published, and monitor the vendor's GitLab work items (727 and 740) for the patched version and affected version ranges. Until patched, restrict who has valid panel credentials, limit the panel's internet exposure (VPN or allowlist), and consider disabling or tightly controlling the server import and admin file-upload features. Review application and web logs for unexpected file uploads or writes to unusual paths.

9.1<1% PoC ×2
  • craftycontrol Crafty Controller
nichelikely low thousands to low tens of thousands of self-hosted panels (order-of-magnitude estimate)