CVE-2026-0392
eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrity-protected. On each launch the application fetches an update descriptor (XML) over TLS but accepts any TLS certificate (a permissive TrustManager and a HostnameVerifier that always returns true), does not verify any digital signature on the update descriptor, and does not verify the Authenticode signature or a checksum of the downloaded installer b
- Vendor
- Latvijas Valsts radio un televīzijas centrs (LVRTC)
- Product
- eParakstītājs 3.0
- Provider severity
- HIGH
- Conflicts
- 1