What is CVE-2026-44097?
This vulnerability allows a low-privileged remote attacker with "operator" access to upload arbitrary files via the REST endpoint intended for firmware updates. This can lead to persistent storage of attacker-controlled files and resource exhaustion, potentially causing a Denial-of-Service (DoS). Access controls and upload restrictions on the affected REST endpoint should be reviewed and hardened.
Azərbaycanca: Bu boşluq "operator" səviyyəli aşağı imtiyazlı uzaqdan hücumçuya firmware yeniləməsi üçün nəzərdə tutulmuş REST endpoint vasitəsilə ixtiyari fayl yükləməyə imkan verir. Bu, resursların tükənməsinə və xidmətin dayandırılmasına (DoS) səbəb ola bilər. Müvafiq REST endpoint-in giriş nəzarəti və yükləmə limitləri nəzərdən keçirilməlidir.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
What privilege level must an attacker have to exploit CVE-2026-44097?
To exploit this vulnerability, an attacker must have low-privileged remote access with "operator" level privileges.
What consequences can CVE-2026-44097 lead to?
This vulnerability can lead to resource exhaustion and potentially cause a Denial-of-Service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.