Junglewise Threat Intelligence

CVE-2026-30278: FunAir FLY is FUN Aviation Navigation arbitrary file overwrite via file import

CVE-2026-30278 · Severity: critical · CVSS 9.8 · Published 2026-03-31

Executive brief

A critical security vulnerability exists in the FLY is FUN Aviation Navigation application, a tool used by pilots for flight planning and navigation. An attacker can exploit the application's file import process to overwrite essential system files. This could allow an unauthorized user to gain control over the device, access sensitive flight data, or disrupt the navigation service, potentially impacting flight safety and operational integrity.

Technical details

A path traversal vulnerability (CWE-22) exists in FLY is FUN Aviation Navigation v35.33 within the file import functionality. By providing a specially crafted file during the import process, an attacker can bypass directory restrictions to overwrite arbitrary internal files on the host system. This vulnerability is reachable over the network without authentication or user interaction. Successful exploitation can lead to arbitrary code execution or the exposure of sensitive information. As of the advisory date, the vulnerability is confirmed in version 35.33.

Affected products

  • FunAir FLY is FUN Aviation Navigation 35.33

Timeline

  • 2026-03-31: disclosed: Initial disclosure of CVE-2026-30278
  • 2026-03-31: advisory: NVD publication date

References