CVE-2026-46459
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
15/07/2026
Last modified:
15/07/2026
Description
ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote attacker to read full facility configurations and write unauthorized data to the sensor database.<br />
This issue has been fixed in version 2.4.18.029
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM



