Junglewise Threat Intelligence

CVE-2026-34028: Wertheim SafeController unauthenticated access to web data

CVE-2026-34028 · Severity: info · CVSS 6.9 · Published 2026-06-15

Technologies: Wertheim SafeController. Vendors: Wertheim.

Executive brief

Wertheim SafeController, a software suite used by banks to manage physical safe deposit boxes and vault rooms, contains a security flaw that allows unauthorized access to sensitive files. An attacker can remotely download internal data, such as audio recordings and system files, without needing a username or password. This could lead to the exposure of confidential customer information or operational data, potentially compromising the privacy and security of the vault management system.

Technical details

The Wertheim SafeController Software (AssemblyVersion 6.15.8328.28014) suffers from a broken access control vulnerability (CWE-425) where specific HTTP endpoints are not protected by an authorization scheme. An unauthenticated, remote attacker can directly access and download files from directories such as /Resources/CompanyId_[ID]/Audio/ and /SafeData/. This vulnerability is part of a larger attack chain; when combined with other identified flaws like path traversal and upload restriction bypasses, it can contribute to authenticated remote code execution (RCE). The vendor has reportedly released a patch, though specific version numbers for the fix were not provided in the advisory.

Affected products

  • Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System) AssemblyVersion 6.15.8328.28014

Timeline

  • 2023-04-03: other: Vulnerability discovered by SEC Consult
  • 2026-06-15: disclosed: CVE published

References

Related threats