Description
CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting in partial information disclosure.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update CMS-WS to version 1.0.26198 or later Update CMS-SE to version 11.0.26198 or later
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 26 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting in partial information disclosure. | |
| Title | CAYIN Technology|CAYIN CMS-WS/CMS-SE - Missing Authentication | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-08-26T08:22:13.081Z
Reserved: 2026-08-26T05:58:50.007Z
Link: CVE-2026-80234
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-26T09:30:04Z
Weaknesses