OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-7395

HIGH · CVSS 8.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated users to access the HTTPPublishAdapterTestServlet in Asset Suite, enabling them to upload configuration files, which can lead to information disclosure and compromise of data integrity. This issue is particularly critical for organizations using Asset Suite in production environments, as it exposes sensitive configuration data to potential attackers. Organizations should prioritize remediation to prevent unauthorized access and maintain the security of their systems.

CVE
CVE-2026-7395
Severity
HIGH
CVSS
8.5
EPSS
0.25%

Original NVD Description

Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPublishAdapterTestServlet is specifically meant for testing purposes to be used in a non-production environment.