# CVE-2026-14947

## Summary

- **CVE ID:** CVE-2026-14947
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-24
- **Published:** Aug 20, 2026
- **Last Modified:** Aug 20, 2026

## Description

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.

## Affected Products

- Frauscher Sensortechnik — FDS 102 (2.8.0)

## References

- [CNA](https://www.certvde.com/en/advisories/VDE-2026-078/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.94%
- **EPSS Percentile:** 58.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._