A vulnerability was found in DumbWareio DumbAssets up to 1.0.11 . It has been declared as critical . Affected by this vulnerability is an unknown functionality of the file /api/delete-file . Such manipulation leads to path traversal. This vulnerability is documented as CVE-2026-45230 . The attack can be executed remotely. There is not any exploit available. Applying a patch is advised to resolve this issue.