CVE-2026-5426

Severity CVSS v4.0:
Pending analysis
Type:
CWE-321 Use of Hard-coded Cryptographic Key
Publication date:
16/04/2026
Last modified:
18/04/2026

Description

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks