CVE Explorer
CVE-2026-4760
From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account.
* Installations based on Panorama Suite 2022-SP1 (22.50.005) are vulnerable unless update PS-2210-02-4079 (or higher) is installed
* Installations based on Panorama Suite 2023 (23.00.004) are vulnerable unless updates PS-2300-03-3078 (or higher) and PS-2300-04-3078 (or higher) and PS-2300-82-3078 (or high
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","modules":["Panorama HMI Web Server"],"platforms":["Windows"],"product":"Panorama Suite","vendor":"CODRA","versions":[{"lessThan":"update PS-2210-02-4079","status":"affected","version":"Panorama Suite 2022-SP1","versionType":"custom"},{"lessThan":"update PS-2300-03-3078 AND PS-2300-04-3078 AND PS-2300-82-3078","status":"affected","version":"Panorama Suite 2023","versionType":"custom"},{"lessThan":"update PS-2500-02-1078 AND PS-2500-04-1078","status":"affected","version":"Panorama Suite 2025","versionType":"custom"},{"lessThan":"update PS-2510-02-1077 AND PS-2510-0…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ac65dc617f4c026f259cb5b2418e27c5be73041b4fee70a1e0199ed44f1cfddc · sha256:c785b963d45200b6… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.7,"baseSeverity":"HIGH","exploitMaturity":"UNREPORTED","privilegesRequired":"NONE","providerUrgency":"RED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/U:Red","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ac65dc617f4c026f259cb5b2418e27c5be73041b4fee70a1e0199ed44f1cfddc · sha256:c785b963d45200b6… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-552","description":"CWE-552 Files or directories accessible to external parties","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ac65dc617f4c026f259cb5b2418e27c5be73041b4fee70a1e0199ed44f1cfddc · sha256:c785b963d45200b6… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://my.codra.net/api/csirt/download?resourceId=1467&fileType=FichierPDF"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ac65dc617f4c026f259cb5b2418e27c5be73041b4fee70a1e0199ed44f1cfddc · sha256:c785b963d45200b6… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.