CVE Explorer
CVE-2026-26928
SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dynamic library. JAR files are correctly verified based on a list of trusted file hashes, and if a file was not on that list, it was checked to see if it had been digitally signed by the vendor. The application doesn't verify hash or vendor's digital signature of uploaded DLL, SO, JNILIB or DYLIB file. The attacker can provide malicious file which will be saved in users /temp folde
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"SzafirHost","vendor":"Krajowa Izba Rozliczeniowa","versions":[{"lessThan":"1.1.0","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2264823356cf305a32e8dbe6b85536655f12a5808307ef81c822276199abed71 · sha256:9945aa785ff393ad… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIG…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2264823356cf305a32e8dbe6b85536655f12a5808307ef81c822276199abed71 · sha256:9945aa785ff393ad… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-354","description":"CWE-354 Improper Validation of Integrity Check Value","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2264823356cf305a32e8dbe6b85536655f12a5808307ef81c822276199abed71 · sha256:9945aa785ff393ad… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["third-party-advisory"],"url":"https://cert.pl/posts/2026/04/CVE-2026-26927"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2264823356cf305a32e8dbe6b85536655f12a5808307ef81c822276199abed71 · sha256:9945aa785ff393ad… · /containers/cna/references/0
{"tags":["product"],"url":"https://www.elektronicznypodpis.pl/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2264823356cf305a32e8dbe6b85536655f12a5808307ef81c822276199abed71 · sha256:9945aa785ff393ad… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.