PatchSiren

Secomea CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Secomea CVE published 2026-09-15

CVE-2026-1759

CVE-2026-1759 is an improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager, which allows for Privilege Escalation. The issue affects GateManager versions 11.5;0 and 11.4.625515072:0, and is fixed in version 11.6 or 11.4.626194074 and above. This vulnerability requires verification of exposure and prompt remediation to prevent potential security breaches. Defenders [truncated]

HIGH Secomea CVE published 2026-09-15

CVE-2026-1758

A session fixation vulnerability exists in Secomea GateManager's webserver module, affecting versions 11.5.0 and 11.4.625515072:0. This issue allows for session fixation attacks, potentially leading to unauthorized access. The vulnerability has been fixed in version 11.6 or 11.4.626194074 and above. Defenders should verify exposure in GateManager deployments, especially those using versions prior to 11.6 [truncated]

MEDIUM Secomea CVE published 2026-03-19

CVE-2025-14716

CVE-2025-14716 is a medium-severity authentication bypass vulnerability affecting Secomea GateManager version 11.4;0. The vulnerability resides in the webserver modules and stems from improper authentication controls (CWE-287), allowing an attacker with low privileges to bypass authentication mechanisms and access high-value information. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) indicates [truncated]