CVE-2026-30286 is a critical arbitrary file overwrite vulnerability affecting Funambol, Inc. Zefiro Cloud v32.0.2026011614, stemming from its file import process. Rated 9.8 CVSS Critical, this flaw allows unauthenticated attackers to remotely overwrite critical internal files with low attack complexity and no user interaction. Successful exploitation can lead to severe consequences, including arbitrary code execution and extensive information exposure. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on CISA's KEV catalog. Despite the lack of current exploitation, its high severity necessitates prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
32.0.2026011614CPE matchmatch criteria | cpe:2.3:a:funambol:zefiro:32.0.2026011614:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.