CVE-2026-30996 Details
Description
An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a directory traversal and read arbitrary files from the system via a crafted GET request.
A path traversal vulnerability has been identified in SoftSul SAC-NFe version 2.0.02 and prior. The issue arises in the file handling logic of download.php and open_pdf.php, where user-supplied file parameters are not properly validated before being used in file system operations. This flaw allows unauthenticated remote attackers to manipulate file paths and access arbitrary files on the server, including sensitive system and application files. The vulnerability is particularly concerning in the context of SAC-NFe's integration with Windows-based fiscal components, as it could lead to the unauthorized disclosure of critical fiscal configuration files and database credentials.
As no official patch has been released by the vendor, it is recommended that system administrators manually apply a security fix to the download.php and open_pdf.php files. The fix involves implementing proper path validation and sanitization to ensure that only authorized files within a designated directory can be accessed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 15, 2026CISA-ADP
Assessed Apr 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cve.joaopaulodeoliveira.dev/cve.php/published/CVE-2026-30996 | [email protected] | AdvisoryExploitRemedy |
| https://cve.joaopaulodeoliveira.dev/cve.php/reserved/softsul-path-transversal | [email protected] | AdvisoryBroken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| SoftSul SAC-NFe | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | New CVE Received | [email protected] |
Volerion