CVE-2026-4760
Last modified
CVE-2026-4760 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account. * Installations based on Panorama Suite 2022-SP1 (22.50.005) are vulnerable unless update PS-2210-02-4079 (or higher) is installed * Installations based on Panorama Suite 2023 (23.00.004) are vulnerable unless updates PS-2300-03-3078 (or higher) and PS-2300-04-3078 (or higher) and PS-2300-82-3078 (or higher) are installed * Installations based on Panorama Suite 2025 (25.00.016) are vulnerable unless updates PS-2500-02-1078 (or higher) and PS-2500-04-1078 (or higher) are installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are vulnerable unless updates PS-2510-02-1077 (or higher) and PS-2510-04-1077 (or higher) are installed Please refer to security bulletin BS-035, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt .. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account. * Installations based on Panorama Suite 2022-SP1 (22.50.005) are vulnerable unless update PS-2210-02-4079 (or higher) is installed * Installations based on Panorama Suite 2023 (23.00.004) are vulnerable unless updates PS-2300-03-3078 (or higher) and PS-2300-04-3078 (or higher) and PS-2300-82-3078 (or higher) are installed * Installations based on Panorama Suite 2025 (25.00.016) are vulnerable unless updates PS-2500-02-1078 (or higher) and PS-2500-04-1078 (or higher) are installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are vulnerable unless updates PS-2510-02-1077 (or higher) and PS-2510-04-1077 (or higher) are installed Please refer to security bulletin BS-035, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt .
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| CODRA | Panorama Suite | >= Panorama Suite 2022-SP1, < update PS-2210-02-4079; >= Panorama Suite 2023, < update PS-2300-03-3078 AND PS-2300-04-3078 AND PS-2300-82-3078; >= Panorama Suite 2025, < update PS-2500-02-1078 AND PS-2500-04-1078; >= Panorama Suite 2025 Updated Dec. 25, < update PS-2510-02-1077 AND PS-2510-04-1077 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-4760?
How severe is CVE-2026-4760?
How do I fix CVE-2026-4760?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4754CWE-79 vulnerability in MolotovCherry Android-ImageMagick7.T…6.1
- CVE-2026-4755CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.T…9.8
- CVE-2026-4756Out-of-bounds Write vulnerability in MolotovCherry Android-I…7.8
- CVE-2026-4757A VAPIX API parameter had improper input validation which co…7.2
- CVE-2026-4758The WP Job Portal plugin for WordPress is vulnerable to arbi…8.8
- CVE-2026-4759Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-4761When a certificate and its private key are installed in the …7.5
- CVE-2026-47612NVIDIA Dynamo for Linux contains a vulnerability in the imag…7.5
- CVE-2026-47613NVIDIA Dynamo for Linux contains a vulnerability where an at…7.5
- CVE-2026-47614NVIDIA Dynamo for Linux contains a vulnerability where an at…7.5
- CVE-2026-47615NVIDIA Dynamo for Linux contains a vulnerability where an at…7.5
- CVE-2026-47616NVIDIA Dynamo for Linux contains a vulnerability in the mult…7.5
Are you affected by CVE-2026-4760?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
