SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-80234

MEDIUM · CVSS 5.3 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

CAYIN CMS-WS and CMS-SE are vulnerable to a Missing Authentication flaw that allows unauthenticated remote attackers to access media file lists, leading to partial information disclosure. Organizations using these products should prioritize addressing this vulnerability to mitigate potential data exposure risks.

CVE
CVE-2026-80234
Severity
MEDIUM
CVSS
5.3
EPSS
0.40%

Original NVD Description

CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting in partial information disclosure.