CVE-2026-26928

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
02/04/2026
Last modified:
03/04/2026

Description

SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dynamic library. JAR files are correctly verified based on a list of trusted file hashes, and if a file was not on that list, it was checked to see if it had been digitally signed by the vendor. The application doesn&amp;#39;t verify hash or vendor&amp;#39;s digital signature of uploaded DLL, SO, JNILIB or DYLIB file. The attacker can provide malicious file which will be saved in users /temp folder and executed by the application.<br /> <br /> This issue was fixed in version 1.1.0.