CVE-2026-70383
8.4Estonian Information System Authority (RIA) · DigiDoc4
A path traversal vulnerability in the DigiDoc4 client allows attackers to bypass directory restrictions, potentially leading to unauthorized file access and system compromise.
Executive summary
A path traversal vulnerability in the DigiDoc4 client could allow an attacker to bypass file system restrictions and gain unauthorized access.
Vulnerability
This is a path traversal vulnerability (CWE-22) that permits an attacker to access restricted directory paths. It requires user interaction to exploit and does not require prior authentication.
Business impact
With a CVSS score of 8.4, this vulnerability presents a significant threat to data confidentiality and integrity. An attacker could exploit this flaw to read or overwrite sensitive files on the host machine, potentially leading to identity theft or the compromise of digital signatures handled by the application.
Remediation
Immediate Action: Upgrade the DigiDoc4 client to version 4.11.0 or later to resolve the path traversal flaw.
Proactive Monitoring: Audit file access logs for unexpected attempts to access system directories by the DigiDoc4 process.
Compensating Controls: Restrict the application environment to a least-privilege user account to limit the impact of a successful path traversal attack.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The DigiDoc4 path traversal vulnerability poses a severe risk to users who rely on the software for secure document handling. Administrators and individual users must update to version 4.11.0 immediately to ensure that file system boundaries are correctly enforced and to prevent unauthorized data access.