CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting in partial information disclosure.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update CMS-WS to version 1.0.26198 or later Update CMS-SE to version 11.0.26198 or later
Workaround
No workaround given by the vendor.
References
History
Wed, 26 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting in partial information disclosure. | |
| Title | CAYIN Technology|CAYIN CMS-WS/CMS-SE - Missing Authentication | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-08-26T08:22:13.081Z
Reserved: 2026-08-26T05:58:50.007Z
Link: CVE-2026-80234
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-26T09:30:04Z
Weaknesses