---
id: CVE-2026-30286
title: 'An arbitrary file overwrite vulnerability in Funambol, Inc'
summary: >-
  An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud
  v32.0.2026011614 allows attackers to overwrite critical internal files via the
  file import process, leading to arbitrary code execution or information
  exposure.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: funambol
product: zefiro
affected:
  - zefiro = 32.0.2026011614
published: '2026-03-31'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-30286'
references:
  - url: 'https://github.com/Secsys-FDU/AF_CVEs/issues/14'
    label: cve@mitre.org
  - url: 'https://play.google.com/store/apps/details?id=com.funambol.zefiro'
    label: cve@mitre.org
  - url: 'https://secsys.fudan.edu.cn/'
    label: cve@mitre.org
  - url: 'https://zefiro.me/'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00641
epssPercentile: 0.49334
ingestedAt: '2026-07-24T20:38:03.250Z'
---

## Overview

An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

## Affected

- `zefiro = 32.0.2026011614`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
