CVE-2026-4312

GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dragonsoft:gcb\/fcb_government_financial_cybersecurity_configuration_audit_software:-:*:*:*:*:*:*:*

History

05 Jun 2026, 14:25

Type Values Removed Values Added
CPE cpe:2.3:a:dragonsoft:gcb\/fcb_government_financial_cybersecurity_configuration_audit_software:-:*:*:*:*:*:*:*
First Time Dragonsoft gcb\/fcb Government Financial Cybersecurity Configuration Audit Software
Dragonsoft
References () https://www.twcert.org.tw/en/cp-139-10785-2cafe-2.html - () https://www.twcert.org.tw/en/cp-139-10785-2cafe-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-10784-4f67d-1.html - () https://www.twcert.org.tw/tw/cp-132-10784-4f67d-1.html - Third Party Advisory
Summary
  • (es) El software de auditoría GCB/FCB desarrollado por DrangSoft tiene una vulnerabilidad de autenticación faltante, que permite a atacantes remotos no autenticados acceder directamente a ciertas API para crear una nueva cuenta administrativa.

17 Mar 2026, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 08:15

Updated : 2026-06-05 14:25


NVD link : CVE-2026-4312

Mitre link : CVE-2026-4312

CVE.ORG link : CVE-2026-4312


JSON object : View

Products Affected

dragonsoft

  • gcb\/fcb_government_financial_cybersecurity_configuration_audit_software
CWE
CWE-306

Missing Authentication for Critical Function