CVE-2026-8480

A vulnerability was discovered on Stormshield Network Security 4.3.0  to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who possesses the revoked certificate to gain administrative access.
Configurations

No configuration.

History

01 Jul 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-01 16:16

Updated : 2026-07-01 19:59


NVD link : CVE-2026-8480

Mitre link : CVE-2026-8480

CVE.ORG link : CVE-2026-8480


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation