CVE Explorer
CVE-2026-1433
uniFLOW Universal Login Manager (ULM) Standalone
contains an information disclosure vulnerability that may allow an
authenticated administrator to access sensitive configuration information
through the ULM Remote User Interface (RUI). Exploitation requires
administrative privileges and may disclose configuration data associated with
SMTP or LDAP integrations. ULM deployments connected to uniFLOW Server or
uniFLOW Online are not affected.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","platforms":["Web Application"],"product":"uniFLOW ULM (Universal Login Manager) Standalone","vendor":"NT-ware","versions":[{"lessThanOrEqual":"5.10","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7f6182df7dac9d72547f295eba6668e8900abb167b50e4b17f64b928743745ac · sha256:567c19dbf109b79b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":4.8,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7f6182df7dac9d72547f295eba6668e8900abb167b50e4b17f64b928743745ac · sha256:567c19dbf109b79b… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-522","description":"CWE-522: Insufficiently Protected Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7f6182df7dac9d72547f295eba6668e8900abb167b50e4b17f64b928743745ac · sha256:567c19dbf109b79b… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["vendor-advisory","mitigation"],"url":"https://ntware.atlassian.net/wiki/spaces/SA/pages/13659504652/2026+Security+Advisory+ULM+Potential+Information+Disclosure"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7f6182df7dac9d72547f295eba6668e8900abb167b50e4b17f64b928743745ac · sha256:567c19dbf109b79b… · /containers/cna/references/1
{"tags":["vendor-advisory"],"url":"https://www.canon-europe.com/psirt/advisory-information"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7f6182df7dac9d72547f295eba6668e8900abb167b50e4b17f64b928743745ac · sha256:567c19dbf109b79b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.