efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targets for path traversal and home containment, but does not validate the dst (destination) parameter used by elfinder_paste. An attacker can copy or move files from within the home directory to any arbitrary destination by setting dst to a base64-encoded traversal path. This bypasses the protected=true security control. This vulnerability is fixed in 4.08.010.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-78"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44258.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44258.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "89782526106010754331986047016442052871",
"length": 1870
},
"id": "CVE-2026-44258-097fd364",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/efwgrp/efw4.x/commit/fe952e6879803c0cc0ff06a565e9d942f12d4fc8",
"target": {
"file": "sources/src/main/javax/efw/file/previewServlet.java",
"function": "doGet"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "89782526106010754331986047016442052871",
"length": 1870
},
"id": "CVE-2026-44258-202748c3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/efwgrp/efw4.x/commit/fe952e6879803c0cc0ff06a565e9d942f12d4fc8",
"target": {
"file": "sources/src/main/jakarta/efw/file/previewServlet.java",
"function": "doGet"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "195264860270728576999647068414862149756",
"length": 770
},
"id": "CVE-2026-44258-37d188e8",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/efwgrp/efw4.x/commit/fe952e6879803c0cc0ff06a565e9d942f12d4fc8",
"target": {
"file": "sources/src/main/java/efw/file/FileManager.java",
"function": "_unZip"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"320618671861691365479427930972051615616",
"29931663741834178740867015509311538954",
"5706814863982540716980096647785502797",
"230437415562700145515869012476482302917"
],
"threshold": 0.9
},
"id": "CVE-2026-44258-7fb72642",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/efwgrp/efw4.x/commit/fe952e6879803c0cc0ff06a565e9d942f12d4fc8",
"target": {
"file": "sources/src/main/javax/efw/file/previewServlet.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"320618671861691365479427930972051615616",
"29931663741834178740867015509311538954",
"5706814863982540716980096647785502797",
"230437415562700145515869012476482302917"
],
"threshold": 0.9
},
"id": "CVE-2026-44258-885204e3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/efwgrp/efw4.x/commit/fe952e6879803c0cc0ff06a565e9d942f12d4fc8",
"target": {
"file": "sources/src/main/jakarta/efw/file/previewServlet.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"255293627626295300523719658593615290738",
"305620081116172530822839982195675158587",
"54211879183095802333488089542858066256"
],
"threshold": 0.9
},
"id": "CVE-2026-44258-8e6e73e4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/efwgrp/efw4.x/commit/fe952e6879803c0cc0ff06a565e9d942f12d4fc8",
"target": {
"file": "sources/src/main/java/efw/file/FileManager.java"
}
}
]
"2026-08-12T16:24:27Z"