CVE-2026-8482
Last modified
CVE-2026-8482 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone with SSH access to the firewall (if SSH multiuser mode is enabled) could possibly get the proxy CA passphrase or TPM password.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible leak of secret information if administration commands have been passed with the CLI command line tool. Someone with SSH access to the firewall (if SSH multiuser mode is enabled) could possibly get the proxy CA passphrase or TPM password.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Stormshield | Stormshield Network Security | >= 4.3.0, <= 4.3.41; >= 4.8.0, <= 4.8.15; >= 5.0.0, <= 5.0.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-8482?
How severe is CVE-2026-8482?
How do I fix CVE-2026-8482?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-84814Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 ve…9.8
- CVE-2026-84815Improper Neutralization of Input During Web Page Generation …5.8
- CVE-2026-84816Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 …7.1
- CVE-2026-84817Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder…7.1
- CVE-2026-84818Unauthenticated Cross Site Scripting (XSS) in Open User Map …7.1
- CVE-2026-84819Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2…7.1
- CVE-2026-84820Unauthenticated Cross Site Scripting (XSS) in Unlimited Elem…7.1
- CVE-2026-84821Unauthenticated Broken Access Control in WP Fast Total Searc…7.5
- CVE-2026-84828A flaw was found in PCS (Pacemaker Configuration System). A …6.5
- CVE-2026-84829The Optimole WordPress plugin before 4.2.12 does not proper…8.8
- CVE-2026-84830SEPPmail Secure Email Gateway before 15.0.7 contains a comma…8.6
- CVE-2026-84831SEPPmail Secure Email Gateway before 15.0.7 creates a fully …7.7
Are you affected by CVE-2026-8482?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
