PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-0392 Latvijas Valsts radio un televīzijas centrs (LVRTC) CVE debrief

The eParakstītājs 3.0 for Windows application has a critical vulnerability (CVE-2026-0392) that allows for arbitrary code execution due to an insecure update mechanism. This mechanism accepts any TLS certificate and does not verify digital signatures or checksums before executing downloaded installers. Affected deployments should prioritize updating to version 1.10.0 or later. The vulnerability impacts operators of eParakstītājs 3.0 for Windows, platform administrators, vulnerability management teams, and security teams responsible for monitoring and mitigating potential threats. Evidence is limited to public sources and may not reflect the full scope of affected systems or potential impacts.

Vendor
Latvijas Valsts radio un televīzijas centrs (LVRTC)
Product
eParakstītājs 3.0
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-08-03
Advisory published
2026-08-03
Advisory updated
2026-08-03

Who should care

Users of eParakstītājs 3.0 for Windows, administrators responsible for maintaining the application, and security teams monitoring for potential threats should prioritize updating to version 1.10.0 or later to address the insecure update mechanism. Additionally, users should verify the authenticity and integrity of updates before installation and implement additional security controls to monitor and restrict application updates. This vulnerability affects operators of eParakstītājs 3.0 for Windows, platform administrators, vulnerability management teams, and security teams responsible for monitoring and mitigating potential threats. Affected deployments should be identified and assessed for potential impacts, with compensating controls implemented where necessary.

Technical summary

The eParakstītājs 3.0 for Windows application has an insecure update mechanism, accepting any TLS certificate and not verifying digital signatures or checksums before executing downloaded installers. This allows for arbitrary code execution on the victim host. The application retrieves and executes its automatic updates over a channel that is not authenticated or integrity-protected. On each launch, the application fetches an update descriptor (XML) over TLS but accepts any TLS certificate (a permissive TrustManager and a HostnameVerifier that always returns true), does not verify any digital signature on the update descriptor, and does not verify the Authenticode signature or a checksum of the downloaded installer before running it.

Defensive priority

Users of eParakstītājs 3.0 for Windows should prioritize updating to version 1.10.0 or later to address the insecure update mechanism.

Recommended defensive actions

  • Update eParakstītājs 3.0 for Windows to version 1.10.0 or later
  • Verify the authenticity and integrity of updates before installation
  • Implement additional security controls to monitor and restrict application updates
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The eParakstītājs 3.0 for Windows application retrieves and executes automatic updates over an unauthenticated and integrity-unprotected channel. The application fetches an update descriptor over TLS but accepts any TLS certificate and does not verify digital signatures or checksums before running the downloaded installer. This insecure update mechanism allows for arbitrary code execution on the victim host. Users should verify the authenticity and integrity of updates before installation and implement additional security controls to monitor and restrict application updates. Evidence is limited to public sources and may not reflect the full scope of affected systems or potential impacts.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T10:16:27.747Z and has not been modified since then.