SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-49180

MEDIUM · CVSS 5.5 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

A vulnerability in Universal Plug and Play (upnp.dll) allows an authorized attacker to exploit improper link resolution before file access, potentially leading to local information disclosure. Organizations utilizing UPnP services should prioritize this issue, as it could expose sensitive data to authenticated users. Implementing proper access controls and monitoring UPnP usage can help mitigate the risk associated with this vulnerability.

CVE
CVE-2026-49180
Severity
MEDIUM
CVSS
5.5
EPSS
0.33%

Original NVD Description

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)