OVERVIEW CVE-2026-40163 affects Saltcorn, an open-source no-code database application builder. Versions prior to 1.4.5, 1.5.5, and 1.6.0-beta.4 are vulnerable to unauthenticated file system manipulation and disclosure. The vulnerability exists in two endpoints: the POST /sync/offline_changes endpoint allows attackers to create arbitrary directories and write malicious JSON files anywhere on the server, while the GET /sync/upload_finished endpoint permits directory traversal and unauthorized file reading. SEVERITY This vulnerability carries a CVSS 3.1 score of 8.2 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack has low complexity, making it easily exploitable by remote threat actors. While the confidentiality impact is limited, the vulnerability poses a significant integrity risk through arbitrary file writing capabilities that could compromise application functionality and data integrity. The FAUCET Risk Score of 50.0/100 indicates moderate risk from an organizational perspective. EXPLOITATION STATUS There is no current evidence of active exploitation in the wild, as the vulnerability remains inactive on the KEV catalog. The EPSS score of 0.001 suggests minimal probability of exploitation within the next 30 days relative to other CVEs. However, given the simplicity of exploitation and lack of authentication requirements, organizations should prioritize patching to versions 1.4.5, 1.5.5, or 1.6.0-beta.4 to prevent potential attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.5CPE matchmatch criteria | cpe:2.3:a:saltcorn:saltcorn:*:*:*:*:*:*:*:* | ||
>= 1.5.0, < 1.5.5CPE matchmatch criteria | cpe:2.3:a:saltcorn:saltcorn:*:*:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:saltcorn:saltcorn:1.6.0:alpha0:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:saltcorn:saltcorn:1.6.0:alpha1:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:saltcorn:saltcorn:1.6.0:alpha10:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.