Bug 2520331 (CVE-2026-70383)

Summary: CVE-2026-70383 DigiDoc4-Client: libdigidocpp: DigiDoc4 client: Arbitrary file overwrite via path traversal
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the DigiDoc4 client. This vulnerability, categorized as an Improper Limitation of a Pathname to a Restricted Directory (Path Traversal), allows a local attacker to write files to arbitrary locations on the system with active user interaction. By exploiting this flaw, an attacker can overwrite existing files, potentially leading to system compromise or denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2521582, 2521583    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-20 14:14:05 UTC
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client.

This issue affects DigiDoc4: from 4.0.0 before 4.11.0.