PatchSiren

ESAFENET CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ESAFENET CVE published 2026-08-05

CVE-2026-18859

A SQL injection vulnerability was identified in ESAFENET CDG up to version 20260615. The vulnerability is located in the /CDGServer3/ukey/usbkey;logindojojs file and can be exploited by manipulating the 'keyid' argument, potentially allowing for remote attacks. The exploit is publicly available, and the CVSS score is 5.5, indicating a medium severity. Organizations should assess and remediate this vulnera [truncated]