CVE-2026-4760

From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account. * Installations based on Panorama Suite 2022-SP1 (22.50.005) are vulnerable unless update PS-2210-02-4079 (or higher) is installed * Installations based on Panorama Suite 2023 (23.00.004) are vulnerable unless updates PS-2300-03-3078 (or higher) and PS-2300-04-3078 (or higher) and PS-2300-82-3078 (or higher) are installed * Installations based on Panorama Suite 2025 (25.00.016) are vulnerable unless updates PS-2500-02-1078 (or higher) and PS-2500-04-1078 (or higher) are installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are vulnerable unless updates PS-2510-02-1077 (or higher) and PS-2510-04-1077 (or higher) are installed Please refer to security bulletin BS-035, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt .
CVSS

No CVSS.

Configurations

No configuration.

History

17 Jun 2026, 10:57

Type Values Removed Values Added
Summary
  • (es) Desde Panorama Web HMI, un atacante puede obtener acceso de lectura a ciertos archivos del servidor Web HMI, si conoce sus rutas y si estos archivos son accesibles para la cuenta de ejecución del proceso Servin. * Las instalaciones basadas en Panorama Suite 2022-SP1 (22.50.005) son vulnerables a menos que se instale la actualización PS-2210-02-4079 (o superior). * Las instalaciones basadas en Panorama Suite 2023 (23.00.004) son vulnerables a menos que se instalen las actualizaciones PS-2300-03-3078 (o superior) y PS-2300-04-3078 (o superior) y PS-2300-82-3078 (o superior). * Las instalaciones basadas en Panorama Suite 2025 (25.00.016) son vulnerables a menos que se instalen las actualizaciones PS-2500-02-1078 (o superior) y PS-2500-04-1078 (o superior). * Las instalaciones basadas en Panorama Suite 2025 Actualizado Dic. 25 (25.10.007) son vulnerables a menos que se instalen las actualizaciones PS-2510-02-1077 (o superior) y PS-2510-04-1077 (o superior). Consulte el boletín de seguridad BS-035, disponible en el sitio web de Panorama CSIRT: https://my.codra.net/en-gb/csirt.

26 Mar 2026, 10:16

Type Values Removed Values Added
Summary (en) From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account. * Installations based on Panorama Suite 2022-SP1 (22.50.005) are vulnerable unless update PS-2210-02-4079 (or higher) is installed * Installations based on Panorama Suite 2023 (23.00.004) are vulnerable unless updates PS-2300-03-3078 (or higher) and PS-2300-04-3078 (or higher) and PS-2300-82-3078 (or higher) are installed * Installations based on Panorama Suite 2025 (25.00.016) are vulnerable unless updates PS-2500-02-1078 (or higher) and PS-2500-04-1078 (or higher) are installed  * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are vulnerable unless updates PS-2510-02-1077 (or higher) and PS-2510-04-1077 (or higher) are installed Please refer to security bulletin BS-035, available on the Panorama CSIRT website:  https://my.codra.net/en-gb/csirt . (en) From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account. * Installations based on Panorama Suite 2022-SP1 (22.50.005) are vulnerable unless update PS-2210-02-4079 (or higher) is installed * Installations based on Panorama Suite 2023 (23.00.004) are vulnerable unless updates PS-2300-03-3078 (or higher) and PS-2300-04-3078 (or higher) and PS-2300-82-3078 (or higher) are installed * Installations based on Panorama Suite 2025 (25.00.016) are vulnerable unless updates PS-2500-02-1078 (or higher) and PS-2500-04-1078 (or higher) are installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are vulnerable unless updates PS-2510-02-1077 (or higher) and PS-2510-04-1077 (or higher) are installed Please refer to security bulletin BS-035, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt .

25 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 13:16

Updated : 2026-06-17 10:57


NVD link : CVE-2026-4760

Mitre link : CVE-2026-4760

CVE.ORG link : CVE-2026-4760


JSON object : View

Products Affected

No product.

CWE
CWE-552

Files or Directories Accessible to External Parties