CVE-2026-40552 is a Remote Command Execution vulnerability affecting multiple BinSoft products. An authorized user can execute system commands by uploading and modifying an attachment's storage path to reference an attacker-controlled remote resource. This issue can be exploited by any unauthenticated attacker when chained with CVE-2026-40550 and CVE-2026-40551. The vulnerability affects all published ver [truncated]
PatchSiren debrief for CVE-2026-40551: Multiple BinSoft products perform client-side authentication, allowing an attacker with access to any application instance connected to the backend server to bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. The issue affects all published versions. The vendor stated that this issue is a direct result [truncated]
CVE-2026-40550 debrief based on the supplied source corpus. The CVE record was published on 2026-04-28T14:16:13.337Z and has not been modified since then. The NVD entry is currently Deferred. Multiple BinSoft products are vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the application. An attacker with access to any running application instance connecte [truncated]