SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-46459

MEDIUM · CVSS 5.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

ICU Scandinavia Boomerang's device receiver endpoints are susceptible to a missing authentication vulnerability, enabling unauthenticated remote attackers to access complete facility configurations and modify data within the sensor database. Organizations using this product should prioritize updating to version 2.4.18.029 to mitigate potential unauthorized access and data manipulation risks.

CVE
CVE-2026-46459
Severity
MEDIUM
CVSS
5.3
EPSS
0.29%

Original NVD Description

ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote attacker to read full facility configurations and write unauthorized data to the sensor database. This issue has been fixed in version 2.4.18.029