SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84840

MEDIUM · CVSS 6.5 EPSS 0.46% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the Bootstrap Setup Endpoint of the Java component tsi-coop tsi-dpdp-cms up to version 0.5.0 allows for missing authentication, potentially enabling remote attackers to exploit the system. Organizations using this software should prioritize upgrading to version 0.5.1 to mitigate the risk, as the exploit is publicly available and could be actively used in attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84840
Severity
MEDIUM
CVSS
6.5
EPSS
0.46%
Java

Original NVD Description

A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. This affects an unknown part of the file InterceptingFilter.java of the component Bootstrap Setup Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used. Upgrading to version 0.5.1 is able to mitigate this issue. Upgrading the affected component is recommended.