PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-34895 WebGeniusLab CVE debrief

CVE-2026-34895 is a HIGH severity vulnerability (CVSS Score: 8.1) in Softlab Core plugin versions < 1.2.11. It allows unauthenticated local file inclusion. This vulnerability was published on June 17, 2026, and last modified on the same day. Users of affected versions should take immediate action to mitigate potential risks. The vulnerability is tracked by Patchstack and listed in the NVD database. No known ransomware campaigns have been associated with this vulnerability.

Vendor
WebGeniusLab
Product
Softlab Core
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-06-17
Advisory published
2026-06-17
Advisory updated
2026-06-17

Who should care

Administrators and users of Softlab Core plugin versions < 1.2.11 should be aware of this vulnerability and take necessary actions to update to a patched version. Security teams should prioritize this vulnerability due to its HIGH severity and potential impact on affected systems.

Technical summary

CVE-2026-34895 is a local file inclusion vulnerability in Softlab Core plugin versions < 1.2.11. The vulnerability allows unauthenticated attackers to include local files, potentially leading to code execution, data exposure, or other malicious activities. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a HIGH severity. The weakness associated with this vulnerability is CWE-98.

Defensive priority

HIGH

Recommended defensive actions

  • Update Softlab Core plugin to version 1.2.11 or later
  • Restrict access to sensitive files and directories
  • Implement additional security measures to prevent local file inclusion attacks
  • Monitor systems for suspicious activity
  • Consider using a Web Application Firewall (WAF) to detect and prevent attacks
  • Regularly review and update software dependencies to ensure timely patching of vulnerabilities

Evidence notes

The information provided is based on data from the NVD database and Patchstack. The CVE record and NVD detail pages provide additional information about the vulnerability. However, due to the limited information available, further research may be necessary to fully understand the vulnerability and its potential impact.

Official resources

This debrief is based on publicly available information and is intended for general informational purposes only.