CVE Explorer
CVE-2026-26927
Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched.
In Szafir SDK Web it is possible to change the URL (HTTP Origin) of the application call location. An unauthenticated attacker can craft a website that is able to launch SzafirHost application with arbitrary arguments via Szafir SDK Web browser addon. No validation will be performed to check whether the address specified in `document_base_url` parameter is in any way related
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Szafir SDK Web","vendor":"Krajowa Izba Rozliczeniowa","versions":[{"lessThan":"0.0.17.4","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:76a6d4de1299ad606bc4fea30ba20cdfc5f017154817865ddc62e4c04e322192 · sha256:b512784b61ef8604… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.1,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:76a6d4de1299ad606bc4fea30ba20cdfc5f017154817865ddc62e4c04e322192 · sha256:b512784b61ef8604… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-348","description":"CWE-348 Use of Less Trusted Source","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:76a6d4de1299ad606bc4fea30ba20cdfc5f017154817865ddc62e4c04e322192 · sha256:b512784b61ef8604… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["third-party-advisory"],"url":"https://cert.pl/posts/2026/04/CVE-2026-26927"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:76a6d4de1299ad606bc4fea30ba20cdfc5f017154817865ddc62e4c04e322192 · sha256:b512784b61ef8604… · /containers/cna/references/0
{"tags":["product"],"url":"https://www.elektronicznypodpis.pl/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:76a6d4de1299ad606bc4fea30ba20cdfc5f017154817865ddc62e4c04e322192 · sha256:b512784b61ef8604… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.