PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-0392 Latvijas Valsts radio un televīzijas centrs (LVRTC) CVE debrief

The eParakstītājs 3.0 for Windows application has a critical vulnerability (CVE-2026-0392) that allows for arbitrary code execution due to an insecure update mechanism. This mechanism accepts any TLS certificate and does not verify digital signatures or checksums before executing downloaded installers. Affected deployments should prioritize updating to version 1.10.0 or later. The vulnerability impacts operators of eParakstītājs 3.0 for Windows, platform administrators, vulnerability management teams, and security teams responsible for monitoring and mitigating potential threats. Evidence is limited to public sources and may not reflect the full scope of affected systems or potential impacts.

Vendor
Latvijas Valsts radio un televīzijas centrs (LVRTC)
Product
eParakstītājs 3.0
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-09-01
Advisory published
2026-08-03
Advisory updated
2026-09-01

Who should care

Users of eParakstītājs 3.0 for Windows, administrators responsible for maintaining the application, and security teams monitoring for potential threats should prioritize updating to version 1.10.0 or later to address the insecure update mechanism. Additionally, users should verify the authenticity and integrity of updates before installation and implement additional security controls to monitor and restrict application updates. This vulnerability affects operators of eParakstītājs 3.0 for Windows, platform administrators, vulnerability management teams, and security teams responsible for monitoring and mitigating potential threats. Affected deployments should be identified and assessed for potential impacts, with compensating controls implemented where necessary.

Technical summary

The eParakstītājs 3.0 for Windows application has an insecure update mechanism, accepting any TLS certificate and not verifying digital signatures or checksums before executing downloaded installers. This allows for arbitrary code execution on the victim host. The application retrieves and executes its automatic updates over a channel that is not authenticated or integrity-protected. On each launch, the application fetches an update descriptor (XML) over TLS but accepts any TLS certificate (a permissive TrustManager and a HostnameVerifier that always returns true), does not verify any digital signature on the update descriptor, and does not verify the Authenticode signature or a checksum of the downloaded installer before running it.

Defensive priority

Users of eParakstītājs 3.0 for Windows should prioritize updating to version 1.10.0 or later to address the insecure update mechanism.

Recommended defensive actions

  • Update eParakstītājs 3.0 for Windows to version 1.10.0 or later
  • Verify the authenticity and integrity of updates before installation
  • Implement additional security controls to monitor and restrict application updates
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The eParakstītājs 3.0 for Windows application retrieves and executes automatic updates over an unauthenticated and integrity-unprotected channel. The application fetches an update descriptor over TLS but accepts any TLS certificate and does not verify digital signatures or checksums before running the downloaded installer. This insecure update mechanism allows for arbitrary code execution on the victim host. Users should verify the authenticity and integrity of updates before installation and implement additional security controls to monitor and restrict application updates. Evidence is limited to public sources and may not reflect the full scope of affected systems or potential impacts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-0392 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-0392

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-0392 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-0392

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cvd.cert.lv/inbox/view/vuln-all-1689187061

    a6d3dc9e-0591-4a13-bce7-0f5b31ff6158

  • Source reference

    Unverified legacy reference

    URL: https://www.eparaksts.lv/lv/par_mums/Jaunumi/Jauna_eParakstitajs_30_versija_1100

    a6d3dc9e-0591-4a13-bce7-0f5b31ff6158

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.