Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks
References
Configurations
No configuration.
History
18 Apr 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
16 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-16 16:16
Updated : 2026-04-18 04:16
NVD link : CVE-2026-5426
Mitre link : CVE-2026-5426
CVE.ORG link : CVE-2026-5426
JSON object : View
Products Affected
No product.
