Executive brief
Wertheim SafeController is a software platform used by banks and financial institutions to manage safe deposit boxes and vault access. A security flaw allows an employee or user with low-level access to bypass security checks and perform restricted actions. This could lead to unauthorized file uploads, the ability to view sensitive branch details, or the downloading of private data, potentially compromising the integrity of the vault management system.
Technical details
The vulnerability is classified as a Missing Authorization (CWE-862) issue within the Wertheim SafeController web application. Multiple backend endpoints fail to verify if the requesting user has the appropriate permissions for the action being performed. An attacker with a valid low-privileged account can directly access these 'hidden' endpoints to switch branch contexts, upload or download arbitrary files, and view sensitive branch-specific details. When combined with other vulnerabilities in the suite (such as path traversal or file upload bypass), this flaw can contribute to a full remote code execution (RCE) chain. The vendor has reportedly released a patch, though specific version numbers for the fix were not provided in the advisory.
Affected products
- Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) AssemblyVersion 6.15.8328.28014
Timeline
- 2023-04-03: other: Vulnerability discovered by SEC Consult
- 2026-06-15: advisory: Public disclosure by SEC Consult and NVD publication