CVE-2026-71284: Fledge-IoT Fledge

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the first extracted tar member's filename (tar_file_names[0]) and builds a shell command via string formatting. Because os.system invokes a shell and no quoting (shlex.quote, list-form subprocess) is applied, an admin uploading a crafted backup archive achieves arbitrary OS command execution.

Affected products

Published 2026-08-05. Last modified 2026-08-26.