CVE Explorer
CVE-2026-39906
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashes by supplying a Windows UNC path as a target file argument through object-unmarshalling techniques. Attackers can capture the leaked NTLMv2 hash and relay it to other hosts to achieve privilege escalation or lateral movement depending on network configuration and patch level.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"WebPerfect Image Suite","vendor":"Unisys","versions":[{"status":"affected","version":"3.0.3960.22810","versionType":"custom"},{"status":"affected","version":"3.0.3960.22604","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:04b8477998b2202ec8a5a01bf881ed049a68f5bc8548cc0bb6dbd6fec3d0077d · sha256:6f3f6e95199caadc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":7,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:04b8477998b2202ec8a5a01bf881ed049a68f5bc8548cc0bb6dbd6fec3d0077d · sha256:6f3f6e95199caadc… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-441","description":"Unintended Proxy or Intermediary ('Confused Deputy')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:04b8477998b2202ec8a5a01bf881ed049a68f5bc8548cc0bb6dbd6fec3d0077d · sha256:6f3f6e95199caadc… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"tags":["technical-description","exploit"],"url":"https://gist.github.com/VAMorales/be3e4ed472c51794493c1256cce16129"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:04b8477998b2202ec8a5a01bf881ed049a68f5bc8548cc0bb6dbd6fec3d0077d · sha256:6f3f6e95199caadc… · /containers/cna/references/0
{"tags":["product"],"url":"https://www.unisys.com/solutions/cai/applications/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:04b8477998b2202ec8a5a01bf881ed049a68f5bc8548cc0bb6dbd6fec3d0077d · sha256:6f3f6e95199caadc… · /containers/cna/references/1
{"tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/unisys-webperfect-image-suite-ntlmv2-hash-leakage-via-net-remoting"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:04b8477998b2202ec8a5a01bf881ed049a68f5bc8548cc0bb6dbd6fec3d0077d · sha256:6f3f6e95199caadc… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.