The described issue affects all published versions. The vendor stated that this issue is a direct result of the architecture model in which the software is distributed, and that it will be mitigated with a corrected installation manual.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 30 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. This issue affects mpGabinet version 23.12.19 and below. | Multiple BinSoft products perform client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. The described issue affects all published versions. The vendor stated that this issue is a direct result of the architecture model in which the software is distributed, and that it will be mitigated with a corrected installation manual. |
| Title | Use of Client-Side Authentication in mpGabinet | Use of Client-Side Authentication in multiple BinSoft products |
| References |
|
Wed, 29 Apr 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Binsoft
Binsoft mpgabinet |
|
| Vendors & Products |
Binsoft
Binsoft mpgabinet |
Tue, 28 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. This issue affects mpGabinet version 23.12.19 and below. | |
| Title | Use of Client-Side Authentication in mpGabinet | |
| Weaknesses | CWE-603 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-30T11:18:14.854Z
Reserved: 2026-04-14T09:44:32.552Z
Link: CVE-2026-40551
Updated: 2026-04-28T14:16:10.502Z
Status : Deferred
Published: 2026-04-28T14:16:13.510
Modified: 2026-09-30T12:17:13.293
Link: CVE-2026-40551
No data.
OpenCVE Enrichment
Updated: 2026-04-29T10:10:44Z
-
CWE-603
Use of Client-Side Authentication