SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-46458

HIGH · CVSS 7.1 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

ICU Scandinavia Boomerang is susceptible to an information disclosure vulnerability that exposes sensitive credential files through static HTTP, enabling unauthenticated remote attackers to access plaintext service account and SMTP credentials by requesting specific XML files. Organizations using affected versions should prioritize patching to version 2.4.18.029 to mitigate the risk of unauthorized access to sensitive information. This issue is particularly critical for businesses relying on this software for secure communications and data handling.

CVE
CVE-2026-46458
Severity
HIGH
CVSS
7.1
EPSS
0.24%

Original NVD Description

ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This allows an unauthenticated remote attacker to retrieve plaintext service account and SMTP credentials by requesting specific XML files from the webroot. This issue has been fixed in version 2.4.18.029