PatchSiren

Optim CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Optim CVE published 2026-03-10

CVE-2026-28267

CVE-2026-28267 documents improper file access permission settings across multiple i-フィルター (i-Filter) products, allowing non-administrative users to create or overwrite files in system and backup directories. The vulnerability is classified as CWE-276 (Incorrect Default Permissions) with a CVSS 4.0 base score of 6.8 (MEDIUM severity). The attack vector is local (AV:L), requires low attack complexity (AC:L) [truncated]