Search
Find a vulnerability
Search criteria
3753 vulnerabilities
CVE-2026-78249 (GCVE-0-2026-78249)
Vulnerability from cvelistv5 – Published: 2026-10-01 07:56 – Updated: 2026-10-01 15:30
VLAI
EPSS
VEX
Summary
A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products listed, specifically in the handling of externally supplied parameters.
If the device receives a specially crafted, malicious request, it may trigger unintended processing.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:30 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
2 references
Impacted products
69 products
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-78249",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:30:34.746566Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:30:58.749Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Apeos 3060 / 2560 / 1860 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 3061 / 2561 / 2061 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.0.3 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 4570 / 3570 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 5330 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 6340 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 7580 / 6580 / 5580 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C2360 / C2060 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C3061 / C2561 / C2061 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.1.103 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C3567 / C3067 / C2567 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.1.3 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C4030/C3530 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C5240 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C7070 / C6570 / C5570 / C4570 / C3570 / C3070 / C2570 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C7071 / C6571 / C5571 / C4571 / C3571 / C3071 / C2571 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.1.3 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C8180 / C7580 / C6580 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint 4560 S / 3960 S / 3360 S Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint 4830 / 4830 JM Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint 6340 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint C3560 S / C3060 S Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.20.105 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint C4030 / C3530 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint C5240 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint C5570 / C4570 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPro C810 / C750 / C650 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Revoria Press E1136 / E1125/ E1110 / E1100 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Revoria Press E1136P/E1125P/E1110P Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Revoria Press EC1100 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.22.11 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Revoria Press EC2100S / EC2100 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.1.4 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Revoria Press SC285S / SC285 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.1.0 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "RevoriaPress SC180 / SC170 Japan model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.23.6 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 3560 / 3060 / 2560 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 3561 / 3061 / 2561 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.0.3 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 5330 / 4830 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 5570 / 4570 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 6340 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 7580 / 6580 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C3060 / C2560 / C2060 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C3061 / C2561 / C2061 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.1.103 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C3567 / C3067 / C2567 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.1.3 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C4030/C3530 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C5240 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C7070 / C6570 / C5570 / C4570 / C3570 / C3070 / C2570 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C7071 / C6571 / C5571 / C4571 / C3571 / C3071 / C2571 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.1.3 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C8180 / C7580 / C6580 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint 4560 S / 3960 S / 3360 S Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint 5330 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint 6340 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint C4030 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint C5240 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint C5570 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPro C810 / C750 / C650 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Revoria Press E1136 / E1125/ E1110 / E1100 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Revoria Press EC1100 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.22.11 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Revoria Press EC2100S / EC2100 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.1.4 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Revoria Press SC285S / SC285 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.1.0 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "RevoriaPress SC180 / SC170 Asia Pacific model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.23.6 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 3561 / 3061 / 2561 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "1.0.3 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 5330/4830 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.50.4 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 5570/4570 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C3060 / C2560 / C2060 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.50.4 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos 3560 / 3060 / 2560 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.50.4 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C4030/C3530 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.50.4 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Apeos C7070 / C6570 / C5570 / C4570 / C3570 / C3070 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint 5330/4830 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.50.4 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPrint C4030/C3530 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.50.4 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "ApeosPro C810 / C750 / C650 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Revoria Press E1136 / E1125 / E1110 /E1100 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.50.5 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Revoria Press EC1100 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.1.6 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Revoria Press EC2100S / EC2100 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.1.4 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Revoria Press SC285S / SC285 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.1.0 or earlier"
}
]
},
{
"defaultStatus": "unaffected",
"product": "RevoriaPress SC180 / SC170 Europe model",
"vendor": "Fujifilm Business Innovation Corp.",
"versions": [
{
"status": "affected",
"version": "21.1.4 or earlier"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003eA path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products listed, specifically in the handling of externally supplied parameters. \n\u003cbr\u003eIf the device receives a specially crafted, malicious request, it may trigger unintended processing.\u0026nbsp;\u003c/div\u003e"
}
],
"value": "A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products listed, specifically in the handling of externally supplied parameters. \n\nIf the device receives a specially crafted, malicious request, it may trigger unintended processing."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T07:56:26.289Z",
"orgId": "47e4fddc-a2f1-48a0-beab-943c84c1c954",
"shortName": "FB"
},
"references": [
{
"url": "https://www.fujifilm.com/fb/en/news/15736e"
},
{
"url": "https://global.sharp/corporate/info/product-security/advisory-list/2026-006/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "47e4fddc-a2f1-48a0-beab-943c84c1c954",
"assignerShortName": "FB",
"cveId": "CVE-2026-78249",
"datePublished": "2026-10-01T07:56:26.289Z",
"dateReserved": "2026-08-24T05:49:42.521Z",
"dateUpdated": "2026-10-01T15:30:58.749Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82824 (GCVE-0-2026-82824)
Vulnerability from cvelistv5 – Published: 2026-10-01 04:57 – Updated: 2026-10-01 15:38
VLAI
EPSS
VEX
Title
Path traversal may allow arbitrary files to be viewed, created, modified, or deleted
Summary
Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files.
This issue affects Hitachi Coding Software Suite: through 3.3.0.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:37 UTC
CWE
- CWE-35 - Path traversal: '.../...//'
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.hitachi-ies.com/common/documents/vuln… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Hitachi Industrial Equipment Systems | Hitachi Coding Software Suite |
Affected:
0 , ≤ 3.3.0
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-82824",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:37:52.305356Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:38:04.914Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Hitachi Coding Software Suite",
"vendor": "Hitachi Industrial Equipment Systems",
"versions": [
{
"changes": [
{
"at": "4.0.0",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.3.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Michael Heinzl"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files.\u003cbr\u003e\u003cp\u003eThis issue affects Hitachi Coding Software Suite: through 3.3.0.\u003c/p\u003e"
}
],
"value": "Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files.\n\n\nThis issue affects Hitachi Coding Software Suite: through 3.3.0."
}
],
"impacts": [
{
"capecId": "CAPEC-126",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-126 Path Traversal"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-35",
"description": "CWE-35 Path traversal: \u0027.../...//\u0027",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:57:58.485Z",
"orgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
"shortName": "Hitachi"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.hitachi-ies.com/common/documents/vulnerability/hcss/Hitachi_Coding_Software_Suite_Public_statement_20260925_EN.pdf"
}
],
"source": {
"advisory": "hitachi-sec-2026-001",
"discovery": "UNKNOWN"
},
"title": "Path traversal may allow arbitrary files to be viewed, created, modified, or deleted",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
"assignerShortName": "Hitachi",
"cveId": "CVE-2026-82824",
"datePublished": "2026-10-01T04:57:58.485Z",
"dateReserved": "2026-08-31T06:46:48.200Z",
"dateUpdated": "2026-10-01T15:38:04.914Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82825 (GCVE-0-2026-82825)
Vulnerability from cvelistv5 – Published: 2026-10-01 04:57 – Updated: 2026-10-01 15:41
VLAI
EPSS
VEX
Title
Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed
Summary
Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized manipulation.
This issue affects Hitachi Coding Software Suite: through 3.3.0.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:41 UTC
CWE
- CWE-306 - Missing authentication for critical function
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.hitachi-ies.com/common/documents/vuln… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Hitachi Industrial Equipment Systems | Hitachi Coding Software Suite |
Affected:
0 , ≤ 3.3.0
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-82825",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:41:04.906534Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:41:16.071Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Hitachi Coding Software Suite",
"vendor": "Hitachi Industrial Equipment Systems",
"versions": [
{
"changes": [
{
"at": "4.0.0",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.3.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Michael Heinzl"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized manipulation.\u003cbr\u003e\u003cp\u003eThis issue affects Hitachi Coding Software Suite: through 3.3.0.\u003c/p\u003e"
}
],
"value": "Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized manipulation.\n\n\nThis issue affects Hitachi Coding Software Suite: through 3.3.0."
}
],
"impacts": [
{
"capecId": "CAPEC-1",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "CWE-306 Missing authentication for critical function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:57:57.577Z",
"orgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
"shortName": "Hitachi"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.hitachi-ies.com/common/documents/vulnerability/hcss/Hitachi_Coding_Software_Suite_Public_statement_20260925_EN.pdf"
}
],
"source": {
"advisory": "hitachi-sec-2026-001",
"discovery": "UNKNOWN"
},
"title": "Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
"assignerShortName": "Hitachi",
"cveId": "CVE-2026-82825",
"datePublished": "2026-10-01T04:57:57.577Z",
"dateReserved": "2026-08-31T06:46:48.200Z",
"dateUpdated": "2026-10-01T15:41:16.071Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82826 (GCVE-0-2026-82826)
Vulnerability from cvelistv5 – Published: 2026-10-01 04:57 – Updated: 2026-10-01 15:41
VLAI
EPSS
VEX
Title
Authentication information or sensitive data may be intercepted in transit
Summary
Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials and sensitive data in transit.
This issue affects Hitachi Coding Software Suite: through 3.3.0.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:41 UTC
CWE
- CWE-319 - Cleartext transmission of sensitive information
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.hitachi-ies.com/common/documents/vuln… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Hitachi Industrial Equipment Systems | Hitachi Coding Software Suite |
Affected:
0 , ≤ 3.3.0
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-82826",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:41:37.258503Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:41:46.971Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Hitachi Coding Software Suite",
"vendor": "Hitachi Industrial Equipment Systems",
"versions": [
{
"changes": [
{
"at": "4.0.0",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.3.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Michael Heinzl"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials and sensitive data in transit.\u003cbr\u003e\u003cp\u003eThis issue affects Hitachi Coding Software Suite: through 3.3.0.\u003c/p\u003e"
}
],
"value": "Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials and sensitive data in transit.\n\n\nThis issue affects Hitachi Coding Software Suite: through 3.3.0."
}
],
"impacts": [
{
"capecId": "CAPEC-102",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-102 Session Sidejacking"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-319",
"description": "CWE-319 Cleartext transmission of sensitive information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:57:56.651Z",
"orgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
"shortName": "Hitachi"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.hitachi-ies.com/common/documents/vulnerability/hcss/Hitachi_Coding_Software_Suite_Public_statement_20260925_EN.pdf"
}
],
"source": {
"advisory": "hitachi-sec-2026-001",
"discovery": "UNKNOWN"
},
"title": "Authentication information or sensitive data may be intercepted in transit",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
"assignerShortName": "Hitachi",
"cveId": "CVE-2026-82826",
"datePublished": "2026-10-01T04:57:56.651Z",
"dateReserved": "2026-08-31T06:46:48.200Z",
"dateUpdated": "2026-10-01T15:41:46.971Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82827 (GCVE-0-2026-82827)
Vulnerability from cvelistv5 – Published: 2026-10-01 04:57 – Updated: 2026-10-01 15:42
VLAI
EPSS
VEX
Title
A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens
Summary
Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions.
This issue affects Hitachi Coding Software Suite: through 3.3.0.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:42 UTC
CWE
- CWE-321 - Use of hard-coded cryptographic key
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.hitachi-ies.com/common/documents/vuln… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Hitachi Industrial Equipment Systems | Hitachi Coding Software Suite |
Affected:
0 , ≤ 3.3.0
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-82827",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:42:02.729318Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:42:16.035Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Hitachi Coding Software Suite",
"vendor": "Hitachi Industrial Equipment Systems",
"versions": [
{
"changes": [
{
"at": "4.0.0",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.3.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Michael Heinzl"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions.\u003cbr\u003e\u003cp\u003eThis issue affects Hitachi Coding Software Suite: through 3.3.0.\u003c/p\u003e"
}
],
"value": "Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions.\n\n\nThis issue affects Hitachi Coding Software Suite: through 3.3.0."
}
],
"impacts": [
{
"capecId": "CAPEC-37",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-37 Retrieve Embedded Sensitive Data"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-321",
"description": "CWE-321 Use of hard-coded cryptographic key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:57:55.728Z",
"orgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
"shortName": "Hitachi"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.hitachi-ies.com/common/documents/vulnerability/hcss/Hitachi_Coding_Software_Suite_Public_statement_20260925_EN.pdf"
}
],
"source": {
"advisory": "hitachi-sec-2026-001",
"discovery": "UNKNOWN"
},
"title": "A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
"assignerShortName": "Hitachi",
"cveId": "CVE-2026-82827",
"datePublished": "2026-10-01T04:57:55.728Z",
"dateReserved": "2026-08-31T06:46:48.200Z",
"dateUpdated": "2026-10-01T15:42:16.035Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82828 (GCVE-0-2026-82828)
Vulnerability from cvelistv5 – Published: 2026-10-01 04:57 – Updated: 2026-10-01 15:46
VLAI
EPSS
VEX
Title
Improper authorization may allow a general user to perform operations equivalent to those available with administrator privileges
Summary
Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations.
This issue affects Hitachi Coding Software Suite: through 3.3.0.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:46 UTC
CWE
- CWE-863 - Incorrect Authorization
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.hitachi-ies.com/common/documents/vuln… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Hitachi Industrial Equipment Systems | Hitachi Coding Software Suite |
Affected:
0 , ≤ 3.3.0
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-82828",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:46:47.351077Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:46:57.132Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Hitachi Coding Software Suite",
"vendor": "Hitachi Industrial Equipment Systems",
"versions": [
{
"changes": [
{
"at": "4.0.0",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.3.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Michael Heinzl"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations.\u003cbr\u003e\u003cp\u003eThis issue affects Hitachi Coding Software Suite: through 3.3.0.\u003c/p\u003e"
}
],
"value": "Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations.\n\n\nThis issue affects Hitachi Coding Software Suite: through 3.3.0."
}
],
"impacts": [
{
"capecId": "CAPEC-233",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-233 Privilege Escalation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863 Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:57:54.765Z",
"orgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
"shortName": "Hitachi"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.hitachi-ies.com/common/documents/vulnerability/hcss/Hitachi_Coding_Software_Suite_Public_statement_20260925_EN.pdf"
}
],
"source": {
"advisory": "hitachi-sec-2026-001",
"discovery": "UNKNOWN"
},
"title": "Improper authorization may allow a general user to perform operations equivalent to those available with administrator privileges",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
"assignerShortName": "Hitachi",
"cveId": "CVE-2026-82828",
"datePublished": "2026-10-01T04:57:54.765Z",
"dateReserved": "2026-08-31T06:46:48.200Z",
"dateUpdated": "2026-10-01T15:46:57.132Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82829 (GCVE-0-2026-82829)
Vulnerability from cvelistv5 – Published: 2026-10-01 04:57 – Updated: 2026-10-01 15:48
VLAI
EPSS
VEX
Title
Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process
Summary
Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials.
This issue affects Hitachi Coding Software Suite: through 3.3.0.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:47 UTC
CWE
- CWE-912 - Hidden Functionality
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.hitachi-ies.com/common/documents/vuln… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Hitachi Industrial Equipment Systems | Hitachi Coding Software Suite |
Affected:
0 , ≤ 3.3.0
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-82829",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:47:24.910441Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:48:20.184Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Hitachi Coding Software Suite",
"vendor": "Hitachi Industrial Equipment Systems",
"versions": [
{
"changes": [
{
"at": "4.0.0",
"status": "unaffected"
}
],
"lessThanOrEqual": "3.3.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Michael Heinzl"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials.\u003cbr\u003e\u003cp\u003eThis issue affects Hitachi Coding Software Suite: through 3.3.0.\u003c/p\u003e"
}
],
"value": "Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials.\n\n\nThis issue affects Hitachi Coding Software Suite: through 3.3.0."
}
],
"impacts": [
{
"capecId": "CAPEC-70",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-70 Try Common or Default Usernames and Passwords"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-912",
"description": "CWE-912 Hidden Functionality",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:57:53.541Z",
"orgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
"shortName": "Hitachi"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.hitachi-ies.com/common/documents/vulnerability/hcss/Hitachi_Coding_Software_Suite_Public_statement_20260925_EN.pdf"
}
],
"source": {
"advisory": "hitachi-sec-2026-001",
"discovery": "UNKNOWN"
},
"title": "Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
"assignerShortName": "Hitachi",
"cveId": "CVE-2026-82829",
"datePublished": "2026-10-01T04:57:53.541Z",
"dateReserved": "2026-08-31T06:46:48.200Z",
"dateUpdated": "2026-10-01T15:48:20.184Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92873 (GCVE-0-2026-92873)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:51 – Updated: 2026-09-30 16:58
VLAI
EPSS
VEX
Summary
Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 16:58 UTC
CWE
- CWE-303 - Incorrect Implementation of Authentication Algorithm
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Pgpool Global Development Group | Pgpool-II |
Affected:
4.7.0 , ≤ 4.7.2
(semver)
Affected: 4.6.0 , ≤ 4.6.7 (semver) Affected: 4.5.0 , ≤ 4.5.12 (semver) Affected: 4.4.0 , ≤ 4.4.17 (semver) Affected: 4.3.0 , ≤ 4.3.20 (semver) Affected: 3.5.x , ≤ 4.2.x (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92873",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T16:58:11.622461Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T16:58:20.542Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Pgpool-II",
"vendor": "Pgpool Global Development Group",
"versions": [
{
"lessThanOrEqual": "4.7.2",
"status": "affected",
"version": "4.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.6.7",
"status": "affected",
"version": "4.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.5.12",
"status": "affected",
"version": "4.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.4.17",
"status": "affected",
"version": "4.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.3.20",
"status": "affected",
"version": "4.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.2.x",
"status": "affected",
"version": "3.5.x",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-303",
"description": "Incorrect Implementation of Authentication Algorithm",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T07:51:52.401Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://pgpool.net/news/2026-09-29/"
},
{
"url": "https://jvn.jp/en/jp/JVN22475874/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-92873",
"datePublished": "2026-09-30T07:51:52.401Z",
"dateReserved": "2026-09-17T06:31:54.745Z",
"dateUpdated": "2026-09-30T16:58:20.542Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92872 (GCVE-0-2026-92872)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:47 – Updated: 2026-09-30 16:59
VLAI
EPSS
VEX
Summary
Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.
Severity
4.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 16:58 UTC
CWE
- CWE-532 - Insertion of sensitive information into log file
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Pgpool Global Development Group | Pgpool-II |
Affected:
4.7.0 , ≤ 4.7.2
(semver)
Affected: 4.6.0 , ≤ 4.6.7 (semver) Affected: 4.5.0 , ≤ 4.5.12 (semver) Affected: 4.4.0 , ≤ 4.4.17 (semver) Affected: 4.3.0 , ≤ 4.3.20 (semver) Affected: 3.5.x , ≤ 4.2.x (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92872",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T16:58:35.298966Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T16:59:12.573Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Pgpool-II",
"vendor": "Pgpool Global Development Group",
"versions": [
{
"lessThanOrEqual": "4.7.2",
"status": "affected",
"version": "4.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.6.7",
"status": "affected",
"version": "4.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.5.12",
"status": "affected",
"version": "4.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.4.17",
"status": "affected",
"version": "4.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.3.20",
"status": "affected",
"version": "4.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.2.x",
"status": "affected",
"version": "3.5.x",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-532",
"description": "Insertion of sensitive information into log file",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T07:47:50.234Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://pgpool.net/news/2026-09-29/"
},
{
"url": "https://jvn.jp/en/jp/JVN22475874/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-92872",
"datePublished": "2026-09-30T07:47:50.234Z",
"dateReserved": "2026-09-17T06:31:54.744Z",
"dateUpdated": "2026-09-30T16:59:12.573Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92871 (GCVE-0-2026-92871)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:47 – Updated: 2026-09-30 15:28
VLAI
EPSS
VEX
Summary
A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:56 UTC
CWE
- CWE-476 - NULL pointer dereference
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Pgpool Global Development Group | Pgpool-II |
Affected:
4.7.0 , ≤ 4.7.2
(semver)
Affected: 4.6.0 , ≤ 4.6.7 (semver) Affected: 4.5.0 , ≤ 4.5.12 (semver) Affected: 4.4.0 , ≤ 4.4.17 (semver) Affected: 4.3.0 , ≤ 4.3.20 (semver) Affected: 3.5.x , ≤ 4.2.x (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92871",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:56:12.370889Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:10.394Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Pgpool-II",
"vendor": "Pgpool Global Development Group",
"versions": [
{
"lessThanOrEqual": "4.7.2",
"status": "affected",
"version": "4.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.6.7",
"status": "affected",
"version": "4.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.5.12",
"status": "affected",
"version": "4.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.4.17",
"status": "affected",
"version": "4.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.3.20",
"status": "affected",
"version": "4.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.2.x",
"status": "affected",
"version": "3.5.x",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-476",
"description": "NULL pointer dereference",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T07:47:32.091Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://pgpool.net/news/2026-09-29/"
},
{
"url": "https://jvn.jp/en/jp/JVN22475874/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-92871",
"datePublished": "2026-09-30T07:47:32.091Z",
"dateReserved": "2026-09-17T06:31:54.744Z",
"dateUpdated": "2026-09-30T15:28:10.394Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93462 (GCVE-0-2026-93462)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:42 – Updated: 2026-10-01 04:54
VLAI
EPSS
VEX
Summary
A missing authentication for critical function vulnerability exists in baserCMS. If this vulnerability is exploited, a remote attacker may obtain sensitive information.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 16:59 UTC
CWE
- CWE-306 - Missing authentication for critical function
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| baserCMS User Community | baserCMS |
Affected:
0 , < 5.4.1
(semver)
Affected: 0 , < 5.3.1 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93462",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T16:59:53.038465Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T17:00:10.783Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "baserCMS",
"vendor": "baserCMS User Community",
"versions": [
{
"lessThan": "5.4.1",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "5.3.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A missing authentication for critical function vulnerability exists in baserCMS. If this vulnerability is exploited, a remote attacker may obtain sensitive information."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing authentication for critical function",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:54:21.181Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://jvn.jp/en/jp/JVN14353754"
},
{
"url": "https://basercms.net/security/JVN_14353754"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-93462",
"datePublished": "2026-09-30T07:42:31.658Z",
"dateReserved": "2026-09-18T01:11:35.023Z",
"dateUpdated": "2026-10-01T04:54:21.181Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93464 (GCVE-0-2026-93464)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:34 – Updated: 2026-10-01 04:54
VLAI
EPSS
VEX
Summary
A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 17:00 UTC
CWE
- CWE-79 - Cross-site scripting (XSS)
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| baserCMS User Community | baserCMS |
Affected:
0 , < 5.4.1
(semver)
Affected: 0 , < 5.3.1 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93464",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T17:00:25.556207Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T17:00:45.379Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "baserCMS",
"vendor": "baserCMS User Community",
"versions": [
{
"lessThan": "5.4.1",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "5.3.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user\u0027s web browser."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Cross-site scripting (XSS)",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:54:41.364Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://jvn.jp/en/jp/JVN14353754"
},
{
"url": "https://basercms.net/security/JVN_14353754"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-93464",
"datePublished": "2026-09-30T07:34:33.353Z",
"dateReserved": "2026-09-18T01:11:35.023Z",
"dateUpdated": "2026-10-01T04:54:41.364Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93460 (GCVE-0-2026-93460)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:34 – Updated: 2026-10-01 04:53
VLAI
EPSS
VEX
Summary
A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 17:01 UTC
CWE
- CWE-79 - Cross-site scripting (XSS)
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| baserCMS User Community | baserCMS |
Affected:
0 , < 5.4.1
(semver)
Affected: 0 , < 5.3.1 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93460",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T17:01:50.030296Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T17:01:59.571Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "baserCMS",
"vendor": "baserCMS User Community",
"versions": [
{
"lessThan": "5.4.1",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "5.3.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user\u0027s web browser."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Cross-site scripting (XSS)",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:53:42.036Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://jvn.jp/en/jp/JVN14353754"
},
{
"url": "https://basercms.net/security/JVN_14353754"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-93460",
"datePublished": "2026-09-30T07:34:09.776Z",
"dateReserved": "2026-09-18T01:11:35.023Z",
"dateUpdated": "2026-10-01T04:53:42.036Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93463 (GCVE-0-2026-93463)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:33 – Updated: 2026-10-02 00:04
VLAI
EPSS
VEX
Summary
A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 17:02 UTC
CWE
- CWE-79 - Cross-site scripting (XSS)
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| baserCMS User Community | baserCMS |
Affected:
0 , < 5.4.1
(semver)
Affected: 0 , < 5.3.1 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93463",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T17:02:34.366438Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T17:02:42.609Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "baserCMS",
"vendor": "baserCMS User Community",
"versions": [
{
"lessThan": "5.4.1",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "5.3.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user\u0027s web browser."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Cross-site scripting (XSS)",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T00:04:22.754Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://jvn.jp/en/jp/JVN14353754"
},
{
"url": "https://basercms.net/security/JVN_14353754"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-93463",
"datePublished": "2026-09-30T07:33:53.821Z",
"dateReserved": "2026-09-18T01:11:35.023Z",
"dateUpdated": "2026-10-02T00:04:22.754Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92870 (GCVE-0-2026-92870)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:21 – Updated: 2026-09-30 19:42
VLAI
EPSS
VEX
Summary
A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 19:41 UTC
CWE
- CWE-121 - Stack-based buffer overflow
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Pgpool Global Development Group | Pgpool-II |
Affected:
4.7.0 , ≤ 4.7.2
(semver)
Affected: 4.6.0 , ≤ 4.6.7 (semver) Affected: 4.5.0 , ≤ 4.5.12 (semver) Affected: 4.4.0 , ≤ 4.4.17 (semver) Affected: 4.3.0 , ≤ 4.3.20 (semver) Affected: 3.5.x , ≤ 4.2.x (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92870",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T19:41:45.298402Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T19:42:09.285Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Pgpool-II",
"vendor": "Pgpool Global Development Group",
"versions": [
{
"lessThanOrEqual": "4.7.2",
"status": "affected",
"version": "4.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.6.7",
"status": "affected",
"version": "4.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.5.12",
"status": "affected",
"version": "4.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.4.17",
"status": "affected",
"version": "4.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.3.20",
"status": "affected",
"version": "4.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.2.x",
"status": "affected",
"version": "3.5.x",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "Stack-based buffer overflow",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T07:21:24.156Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://pgpool.net/news/2026-09-29/"
},
{
"url": "https://jvn.jp/en/jp/JVN22475874/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-92870",
"datePublished": "2026-09-30T07:21:24.156Z",
"dateReserved": "2026-09-17T06:31:54.744Z",
"dateUpdated": "2026-09-30T19:42:09.285Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92869 (GCVE-0-2026-92869)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:21 – Updated: 2026-09-30 19:41
VLAI
EPSS
VEX
Summary
An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 19:40 UTC
CWE
- CWE-787 - Out-of-bounds Write
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Pgpool Global Development Group | Pgpool-II |
Affected:
4.7.0 , ≤ 4.7.2
(semver)
Affected: 4.6.0 , ≤ 4.6.7 (semver) Affected: 4.5.0 , ≤ 4.5.12 (semver) Affected: 4.4.0 , ≤ 4.4.17 (semver) Affected: 4.3.0 , ≤ 4.3.20 (semver) Affected: 3.5.x , ≤ 4.2.x (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92869",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T19:40:57.866496Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T19:41:10.963Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Pgpool-II",
"vendor": "Pgpool Global Development Group",
"versions": [
{
"lessThanOrEqual": "4.7.2",
"status": "affected",
"version": "4.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.6.7",
"status": "affected",
"version": "4.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.5.12",
"status": "affected",
"version": "4.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.4.17",
"status": "affected",
"version": "4.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.3.20",
"status": "affected",
"version": "4.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.2.x",
"status": "affected",
"version": "3.5.x",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-787",
"description": "Out-of-bounds Write",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T07:21:09.653Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://pgpool.net/news/2026-09-29/"
},
{
"url": "https://jvn.jp/en/jp/JVN22475874/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-92869",
"datePublished": "2026-09-30T07:21:09.653Z",
"dateReserved": "2026-09-17T06:31:54.744Z",
"dateUpdated": "2026-09-30T19:41:10.963Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92868 (GCVE-0-2026-92868)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:20 – Updated: 2026-09-30 19:40
VLAI
EPSS
VEX
Summary
An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.
Severity
6.5 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 19:40 UTC
CWE
- CWE-295 - Improper certificate validation
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Pgpool Global Development Group | Pgpool-II |
Affected:
4.7.0 , ≤ 4.7.2
(semver)
Affected: 4.6.0 , ≤ 4.6.7 (semver) Affected: 4.5.0 , ≤ 4.5.12 (semver) Affected: 4.4.0 , ≤ 4.4.17 (semver) Affected: 4.3.0 , ≤ 4.3.20 (semver) Affected: 4.0.x , ≤ 4.2.x (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92868",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T19:40:06.099584Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T19:40:27.576Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Pgpool-II",
"vendor": "Pgpool Global Development Group",
"versions": [
{
"lessThanOrEqual": "4.7.2",
"status": "affected",
"version": "4.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.6.7",
"status": "affected",
"version": "4.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.5.12",
"status": "affected",
"version": "4.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.4.17",
"status": "affected",
"version": "4.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.3.20",
"status": "affected",
"version": "4.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.2.x",
"status": "affected",
"version": "4.0.x",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-295",
"description": "Improper certificate validation",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T07:20:48.300Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://pgpool.net/news/2026-09-29/"
},
{
"url": "https://jvn.jp/en/jp/JVN22475874/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-92868",
"datePublished": "2026-09-30T07:20:48.300Z",
"dateReserved": "2026-09-17T06:31:54.744Z",
"dateUpdated": "2026-09-30T19:40:27.576Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92867 (GCVE-0-2026-92867)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:20 – Updated: 2026-09-30 16:57
VLAI
EPSS
VEX
Summary
An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 16:57 UTC
CWE
- CWE-787 - Out-of-bounds Write
Assigner
References
2 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Pgpool Global Development Group | Pgpool-II |
Affected:
4.7.0 , ≤ 4.7.2
(semver)
Affected: 4.6.0 , ≤ 4.6.7 (semver) Affected: 4.5.0 , ≤ 4.5.12 (semver) Affected: 4.4.0 , ≤ 4.4.17 (semver) Affected: 4.3.0 , ≤ 4.3.20 (semver) Affected: 3.5.x , ≤ 4.2.x (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92867",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T16:57:37.566411Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T16:57:47.609Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Pgpool-II",
"vendor": "Pgpool Global Development Group",
"versions": [
{
"lessThanOrEqual": "4.7.2",
"status": "affected",
"version": "4.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.6.7",
"status": "affected",
"version": "4.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.5.12",
"status": "affected",
"version": "4.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.4.17",
"status": "affected",
"version": "4.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.3.20",
"status": "affected",
"version": "4.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.2.x",
"status": "affected",
"version": "3.5.x",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-787",
"description": "Out-of-bounds Write",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T07:20:27.931Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://pgpool.net/news/2026-09-29/"
},
{
"url": "https://jvn.jp/en/jp/JVN22475874/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-92867",
"datePublished": "2026-09-30T07:20:27.931Z",
"dateReserved": "2026-09-17T06:31:54.744Z",
"dateUpdated": "2026-09-30T16:57:47.609Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97150 (GCVE-0-2026-97150)
Vulnerability from cvelistv5 – Published: 2026-09-30 07:12 – Updated: 2026-09-30 14:38
VLAI
EPSS
VEX
Summary
When converting baserCMS4-style addons to baserCMS5-style ones,
BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed.
Arbitrary files on the system may be read or deleted by an administrative user.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:38 UTC
CWE
- CWE-829 - Inclusion of functionality from untrusted control sphere
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| baserCMS Users Community | BcAddonMigrator |
Affected:
0 , ≤ 5.2.0
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97150",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:38:52.204555Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:38:59.606Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "BcAddonMigrator",
"vendor": "baserCMS Users Community",
"versions": [
{
"lessThanOrEqual": "5.2.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "When converting baserCMS4-style addons to baserCMS5-style ones,\r\nBcAddonMigrator includes \"config.php\" from the addon, which means the PHP code in the file is executed.\r\nArbitrary files on the system may be read or deleted by an administrative user."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 8.6,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-829",
"description": "Inclusion of functionality from untrusted control sphere",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T07:12:22.738Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://jvn.jp/en/jp/JVN21754394"
},
{
"url": "https://basercms.net/security/JVN_21754394"
},
{
"url": "https://github.com/baserproject/BcAddonMigrator/commit/e836bc875e26910e1b5862f96cf280b4f064c104"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-97150",
"datePublished": "2026-09-30T07:12:22.738Z",
"dateReserved": "2026-09-24T02:49:08.352Z",
"dateUpdated": "2026-09-30T14:38:59.606Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-81310 (GCVE-0-2026-81310)
Vulnerability from cvelistv5 – Published: 2026-09-30 01:51 – Updated: 2026-09-30 16:57
VLAI
EPSS
VEX
Summary
Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance.
Severity
6.6 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 16:57 UTC
CWE
- CWE-59 - Improper link resolution before file access ('Link Following')
Assigner
References
2 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| PFU Limited | Image Scanner Driver for Linux (fi Series) |
Affected:
2.0.0
Affected: 2.1.0 , ≤ 2.1.1 (semver) Affected: 2.3.2 Affected: 2.5.0 Affected: 2.7.0 , ≤ 2.7.1 (semver) Affected: 2.8.0 , ≤ 2.8.2 (semver) |
|
| PFU Limited | Image Scanner Driver for Linux (SP Series) |
Affected:
2.0.0
Affected: 2.1.0 , ≤ 2.1.1-4 (semver) Affected: 2.2.0 , ≤ 2.2.2 (semver) Affected: 2.3.0 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-81310",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T16:57:00.957114Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T16:57:19.086Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Image Scanner Driver for Linux (fi Series)",
"vendor": "PFU Limited",
"versions": [
{
"status": "affected",
"version": "2.0.0"
},
{
"lessThanOrEqual": "2.1.1",
"status": "affected",
"version": "2.1.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.3.2"
},
{
"status": "affected",
"version": "2.5.0"
},
{
"lessThanOrEqual": "2.7.1",
"status": "affected",
"version": "2.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "2.8.2",
"status": "affected",
"version": "2.8.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Image Scanner Driver for Linux (SP Series)",
"vendor": "PFU Limited",
"versions": [
{
"status": "affected",
"version": "2.0.0"
},
{
"lessThanOrEqual": "2.1.1-4",
"status": "affected",
"version": "2.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "2.2.2",
"status": "affected",
"version": "2.2.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.3.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.6,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 5.2,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-59",
"description": "Improper link resolution before file access (\u0027Link Following\u0027)",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T01:51:54.487Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://www.pfu.ricoh.com/global/products_security/vul2026000001e.html"
},
{
"url": "https://jvn.jp/en/vu/JVNVU96968110/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-81310",
"datePublished": "2026-09-30T01:51:54.487Z",
"dateReserved": "2026-09-04T00:52:01.540Z",
"dateUpdated": "2026-09-30T16:57:19.086Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-78229 (GCVE-0-2026-78229)
Vulnerability from cvelistv5 – Published: 2026-09-30 01:51 – Updated: 2026-09-30 15:28
VLAI
EPSS
VEX
Summary
Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affected product is installed may execute an arbitrary OS command by making certain preparations.
Severity
6.7 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:57 UTC
CWE
- CWE-78 - Improper neutralization of special elements used in an OS command ('OS Command Injection')
Assigner
References
2 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| PFU Limited | Image Scanner Driver for Linux (fi Series) |
Affected:
2.0.0
Affected: 2.1.0 , ≤ 2.1.1 (semver) Affected: 2.3.2 Affected: 2.5.0 Affected: 2.7.0 , ≤ 2.7.1 (semver) Affected: 2.8.0 , ≤ 2.8.2 (semver) |
|
| PFU Limited | Image Scanner Driver for Linux (SP Series) |
Affected:
2.0.0
Affected: 2.1.0 , ≤ 2.1.1-4 (semver) Affected: 2.2.0 , ≤ 2.2.2 (semver) Affected: 2.3.0 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-78229",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:57:11.023085Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:12.170Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Image Scanner Driver for Linux (fi Series)",
"vendor": "PFU Limited",
"versions": [
{
"status": "affected",
"version": "2.0.0"
},
{
"lessThanOrEqual": "2.1.1",
"status": "affected",
"version": "2.1.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.3.2"
},
{
"status": "affected",
"version": "2.5.0"
},
{
"lessThanOrEqual": "2.7.1",
"status": "affected",
"version": "2.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "2.8.2",
"status": "affected",
"version": "2.8.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Image Scanner Driver for Linux (SP Series)",
"vendor": "PFU Limited",
"versions": [
{
"status": "affected",
"version": "2.0.0"
},
{
"lessThanOrEqual": "2.1.1-4",
"status": "affected",
"version": "2.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "2.2.2",
"status": "affected",
"version": "2.2.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "2.3.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affected product is installed may execute an arbitrary OS command by making certain preparations."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "Improper neutralization of special elements used in an OS command (\u0027OS Command Injection\u0027)",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T01:51:37.656Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://www.pfu.ricoh.com/global/products_security/vul2026000001e.html"
},
{
"url": "https://jvn.jp/en/vu/JVNVU96968110/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-78229",
"datePublished": "2026-09-30T01:51:37.656Z",
"dateReserved": "2026-09-04T00:52:00.615Z",
"dateUpdated": "2026-09-30T15:28:12.170Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95104 (GCVE-0-2026-95104)
Vulnerability from cvelistv5 – Published: 2026-09-28 08:14 – Updated: 2026-09-30 13:45
VLAI
EPSS
VEX
Summary
Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 13:45 UTC
CWE
- CWE-121 - Stack-based buffer overflow
Assigner
References
2 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| BUFFALO INC. | WSR-300HP |
Affected:
0 , < Ver.2.55
(semver)
|
|
| BUFFALO INC. | WEX-G300 |
Affected:
0 , < Ver.1.71
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95104",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T13:45:03.286394Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T13:45:14.990Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WSR-300HP",
"vendor": "BUFFALO INC.",
"versions": [
{
"lessThan": "Ver.2.55",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "WEX-G300",
"vendor": "BUFFALO INC.",
"versions": [
{
"lessThan": "Ver.1.71",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-121",
"description": "Stack-based buffer overflow",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T08:14:36.848Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://www.buffalo.jp/news/detail/20260928-01.html"
},
{
"url": "https://jvn.jp/en/vu/JVNVU94863997/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-95104",
"datePublished": "2026-09-28T08:14:36.848Z",
"dateReserved": "2026-09-24T08:54:17.057Z",
"dateUpdated": "2026-09-30T13:45:14.990Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86530 (GCVE-0-2026-86530)
Vulnerability from cvelistv5 – Published: 2026-09-28 08:14 – Updated: 2026-09-30 12:33
VLAI
EPSS
VEX
Summary
BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and execute an arbitrary OS command.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 12:33 UTC
CWE
- CWE-78 - Improper neutralization of special elements used in an OS command ('OS Command Injection')
Assigner
References
2 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| BUFFALO INC. | WSR-300HP |
Affected:
0 , < Ver.2.55
(semver)
|
|
| BUFFALO INC. | WEX-G300 |
Affected:
0 , < Ver.1.71
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86530",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T12:33:28.028156Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T12:33:40.894Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WSR-300HP",
"vendor": "BUFFALO INC.",
"versions": [
{
"lessThan": "Ver.2.55",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "WEX-G300",
"vendor": "BUFFALO INC.",
"versions": [
{
"lessThan": "Ver.1.71",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and execute an arbitrary OS command."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 8.6,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "Improper neutralization of special elements used in an OS command (\u0027OS Command Injection\u0027)",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T08:14:00.049Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://www.buffalo.jp/news/detail/20260928-01.html"
},
{
"url": "https://jvn.jp/en/vu/JVNVU94863997/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-86530",
"datePublished": "2026-09-28T08:14:00.049Z",
"dateReserved": "2026-09-24T08:54:17.872Z",
"dateUpdated": "2026-09-30T12:33:40.894Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-75553 (GCVE-0-2026-75553)
Vulnerability from cvelistv5 – Published: 2026-09-25 06:25 – Updated: 2026-09-25 13:34
VLAI
EPSS
VEX
Summary
Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-25 13:32 UTC
CWE
- CWE-321 - Use of hard-coded cryptographic key
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Tohoku Electric Power Company, Incorporated | Tohoku Electric Power "Yorisou e Net" Android App |
Affected:
0 , < 2.8.0
(semver)
|
|
| Tohoku Electric Power Company, Incorporated | Tohoku Electric Power "Yorisou e Net" iOS App |
Affected:
0 , < 2.8.0
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-75553",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T13:32:10.369668Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T13:34:46.656Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Tohoku Electric Power \"Yorisou e Net\" Android App",
"vendor": "Tohoku Electric Power Company, Incorporated",
"versions": [
{
"lessThan": "2.8.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Tohoku Electric Power \"Yorisou e Net\" iOS App",
"vendor": "Tohoku Electric Power Company, Incorporated",
"versions": [
{
"lessThan": "2.8.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Smartphone application Tohoku Electric Power \"Yorisou e Net\" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from the affected product."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 2.4,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 2.4,
"baseSeverity": "LOW",
"vectorString": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-321",
"description": "Use of hard-coded cryptographic key",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T06:25:15.249Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://play.google.com/store/apps/details?id=jp.co.tohokuepco.enet\u0026hl=ja"
},
{
"url": "https://apps.apple.com/jp/app/%E6%9D%B1%E5%8C%97%E9%9B%BB%E5%8A%9B-%E3%82%88%E3%82%8A%E3%81%9D%E3%81%86%EF%BD%85%E3%81%AD%E3%81%A3%E3%81%A8/id1420949327?l=en-US"
},
{
"url": "https://jvn.jp/en/jp/JVN93985674/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-75553",
"datePublished": "2026-09-25T06:25:15.249Z",
"dateReserved": "2026-08-24T07:04:44.688Z",
"dateUpdated": "2026-09-25T13:34:46.656Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-15688 (GCVE-0-2026-15688)
Vulnerability from cvelistv5 – Published: 2026-09-17 08:15 – Updated: 2026-09-17 12:25
VLAI
EPSS
VEX
Title
Password Authentication Bypass Vulnerability in GX Works3 and Motion Control Setting
Summary
Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the executable module in memory, and thereby may be able to view, tamper with, destroy, or delete control programs.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-17 12:24 UTC
CWE
- CWE-303 - Incorrect Implementation of Authentication Algorithm
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://www.mitsubishielectric.com/psirt/vulnerab… | vendor-advisory |
| https://jvn.jp/vu/JVNVU99700314 | government-resource |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Mitsubishi Electric Corporation | GX Works3 |
Affected:
All versions
|
|
| Mitsubishi Electric Corporation | Motion Control Setting |
Affected:
All versions
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-15688",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T12:24:48.176339Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T12:25:10.782Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "GX Works3",
"vendor": "Mitsubishi Electric Corporation",
"versions": [
{
"status": "affected",
"version": "All versions"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Motion Control Setting",
"vendor": "Mitsubishi Electric Corporation",
"versions": [
{
"status": "affected",
"version": "All versions"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the executable module in memory, and thereby may be able to view, tamper with, destroy, or delete control programs."
}
],
"value": "Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the executable module in memory, and thereby may be able to view, tamper with, destroy, or delete control programs."
}
],
"impacts": [
{
"descriptions": [
{
"lang": "en",
"value": "Password Authentication Bypass"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-303",
"description": "CWE-303 Incorrect Implementation of Authentication Algorithm",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T08:15:27.769Z",
"orgId": "e0f77b61-78fd-4786-b3fb-1ee347a748ad",
"shortName": "Mitsubishi"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-007_en.pdf"
},
{
"tags": [
"government-resource"
],
"url": "https://jvn.jp/vu/JVNVU99700314"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Password Authentication Bypass Vulnerability in GX Works3 and Motion Control Setting",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "e0f77b61-78fd-4786-b3fb-1ee347a748ad",
"assignerShortName": "Mitsubishi",
"cveId": "CVE-2026-15688",
"datePublished": "2026-09-17T08:15:27.769Z",
"dateReserved": "2026-07-14T00:29:02.381Z",
"dateUpdated": "2026-09-17T12:25:10.782Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84408 (GCVE-0-2026-84408)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:30 – Updated: 2026-09-16 14:56
VLAI
EPSS
VEX
Summary
QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to execute arbitrary commands with SYSTEM privileges.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 14:56 UTC
CWE
- CWE-782 - Exposed IOCTL with insufficient access control
Assigner
References
2 references
Impacted products
3 products
| Vendor | Product | Version | |
|---|---|---|---|
| QualitySoft Corporation | QND Premium |
Affected:
0 , ≤ Ver.11.1i
(semver)
|
|
| QualitySoft Corporation | QND Standard |
Affected:
0 , ≤ Ver.11.1i
(semver)
|
|
| QualitySoft Corporation | QND Advance |
Affected:
0 , ≤ Ver.11.0.9i
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-84408",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T14:56:03.385814Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T14:56:14.956Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "QND Premium",
"vendor": "QualitySoft Corporation",
"versions": [
{
"lessThanOrEqual": "Ver.11.1i",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "QND Standard",
"vendor": "QualitySoft Corporation",
"versions": [
{
"lessThanOrEqual": "Ver.11.1i",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "QND Advance",
"vendor": "QualitySoft Corporation",
"versions": [
{
"lessThanOrEqual": "Ver.11.0.9i",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC where the affected product\u0027s client is installed to execute arbitrary commands with SYSTEM privileges."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-782",
"description": "Exposed IOCTL with insufficient access control",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:30:01.520Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://www.qualitysoft.com/product/qnd_vulnerabilities_2026/"
},
{
"url": "https://jvn.jp/en/jp/JVN95825631/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-84408",
"datePublished": "2026-09-16T07:30:01.520Z",
"dateReserved": "2026-09-10T06:51:56.985Z",
"dateUpdated": "2026-09-16T14:56:14.956Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-81326 (GCVE-0-2026-81326)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:29 – Updated: 2026-09-16 14:57
VLAI
EPSS
VEX
Summary
QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and password.
Severity
5.5 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 14:56 UTC
CWE
- CWE-321 - Use of hard-coded cryptographic key
Assigner
References
2 references
Impacted products
3 products
| Vendor | Product | Version | |
|---|---|---|---|
| QualitySoft Corporation | QND Premium |
Affected:
0 , ≤ Ver.11.1i
(semver)
|
|
| QualitySoft Corporation | QND Standard |
Affected:
0 , ≤ Ver.11.1i
(semver)
|
|
| QualitySoft Corporation | QND Advance |
Affected:
0 , ≤ Ver.11.0.9i
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-81326",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T14:56:57.418397Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T14:57:07.233Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "QND Premium",
"vendor": "QualitySoft Corporation",
"versions": [
{
"lessThanOrEqual": "Ver.11.1i",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "QND Standard",
"vendor": "QualitySoft Corporation",
"versions": [
{
"lessThanOrEqual": "Ver.11.1i",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "QND Advance",
"vendor": "QualitySoft Corporation",
"versions": [
{
"lessThanOrEqual": "Ver.11.0.9i",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product\u0027s client is installed to obtain administrator credentials, including an ID and password."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-321",
"description": "Use of hard-coded cryptographic key",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:29:40.013Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://www.qualitysoft.com/product/qnd_vulnerabilities_2026/"
},
{
"url": "https://jvn.jp/en/jp/JVN95825631/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-81326",
"datePublished": "2026-09-16T07:29:40.013Z",
"dateReserved": "2026-09-10T06:51:56.086Z",
"dateUpdated": "2026-09-16T14:57:07.233Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-88263 (GCVE-0-2026-88263)
Vulnerability from cvelistv5 – Published: 2026-09-16 07:29 – Updated: 2026-09-16 15:02
VLAI
EPSS
VEX
Summary
XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 15:01 UTC
CWE
- CWE-306 - Missing authentication for critical function
Assigner
References
2 references
Impacted products
3 products
| Vendor | Product | Version | |
|---|---|---|---|
| XikeStor | SKS8310-8X |
Affected:
0 , < V1.04.B09
(semver)
|
|
| XikeStor | SKS8300-8T |
Affected:
0 , < V1.04.B09
(semver)
|
|
| XikeStor | SKS8300-12E2T2X |
Affected:
0 , < V1.04.B09
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-88263",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T15:01:05.622997Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T15:02:24.681Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "SKS8310-8X",
"vendor": "XikeStor",
"versions": [
{
"lessThan": "V1.04.B09",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "SKS8300-8T",
"vendor": "XikeStor",
"versions": [
{
"lessThan": "V1.04.B09",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "SKS8300-12E2T2X",
"vendor": "XikeStor",
"versions": [
{
"lessThan": "V1.04.B09",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing authentication for critical function",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T07:29:24.441Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://www.xikestor.com/security-advisory/"
},
{
"url": "https://jvn.jp/en/jp/JVN45281119/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-88263",
"datePublished": "2026-09-16T07:29:24.441Z",
"dateReserved": "2026-09-10T00:56:14.741Z",
"dateUpdated": "2026-09-16T15:02:24.681Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80217 (GCVE-0-2026-80217)
Vulnerability from cvelistv5 – Published: 2026-09-15 08:50 – Updated: 2026-09-15 13:21
VLAI
EPSS
VEX
Summary
Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-15 13:20 UTC
CWE
- CWE-912 - Hidden functionality
Assigner
References
2 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| LITE-ON Technology Corporation | FF-RFI079I4 |
Affected:
0 , < 02.01.15
(semver)
|
|
| LITE-ON Technology Corporation | FF-RFI078I4 |
Affected:
0 , < 02.01.15
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-80217",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T13:20:27.171964Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T13:21:42.918Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "FF-RFI079I4",
"vendor": "LITE-ON Technology Corporation",
"versions": [
{
"lessThan": "02.01.15",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "FF-RFI078I4",
"vendor": "LITE-ON Technology Corporation",
"versions": [
{
"lessThan": "02.01.15",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-912",
"description": "Hidden functionality",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T08:50:13.630Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://jvn.jp/en/jp/JVN02049764/"
},
{
"url": "https://5g.liteon.com/security/flexfi/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-80217",
"datePublished": "2026-09-15T08:50:13.630Z",
"dateReserved": "2026-09-07T08:29:55.575Z",
"dateUpdated": "2026-09-15T13:21:42.918Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77853 (GCVE-0-2026-77853)
Vulnerability from cvelistv5 – Published: 2026-09-15 08:49 – Updated: 2026-09-15 13:31
VLAI
EPSS
VEX
Summary
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-15 13:30 UTC
CWE
- CWE-78 - Improper neutralization of special elements used in an OS command ('OS Command Injection')
Assigner
References
2 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| LITE-ON Technology Corporation | FF-RFI079I4 |
Affected:
0 , < 02.01.15
(semver)
|
|
| LITE-ON Technology Corporation | FF-RFI078I4 |
Affected:
0 , < 02.01.15
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77853",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T13:30:26.116157Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T13:31:40.999Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "FF-RFI079I4",
"vendor": "LITE-ON Technology Corporation",
"versions": [
{
"lessThan": "02.01.15",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "FF-RFI078I4",
"vendor": "LITE-ON Technology Corporation",
"versions": [
{
"lessThan": "02.01.15",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper neutralization of special elements used in an OS command (\u0027OS Command Injection\u0027) issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product\u0027s M-Plane (NETCONF) may execute arbitrary OS commands."
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "Improper neutralization of special elements used in an OS command (\u0027OS Command Injection\u0027)",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T08:49:58.307Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://5g.liteon.com/security/flexfi/"
},
{
"url": "https://jvn.jp/en/jp/JVN02049764/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2026-77853",
"datePublished": "2026-09-15T08:49:58.307Z",
"dateReserved": "2026-09-07T08:29:54.584Z",
"dateUpdated": "2026-09-15T13:31:40.999Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}