CVE-2026-70383: Estonian Information System Authority Ria DIGIDOC4
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client. This issue affects DigiDoc4: from 4.0.0 before 4.11.0.
Affected products
- Estonian Information System Authority Ria DIGIDOC4: from 4.0.0, before 4.11.0 (fixed in 4.11.0)
Published 2026-08-20. Last modified 2026-09-01.