PatchSiren cyber security CVE debrief
CVE-2026-34895 WebGeniusLab CVE debrief
CVE-2026-34895 is a HIGH severity vulnerability (CVSS Score: 8.1) in Softlab Core plugin versions < 1.2.11. It allows unauthenticated local file inclusion. This vulnerability was published on June 17, 2026, and last modified on the same day. Users of affected versions should take immediate action to mitigate potential risks. The vulnerability is tracked by Patchstack and listed in the NVD database. No known ransomware campaigns have been associated with this vulnerability.
- Vendor
- WebGeniusLab
- Product
- Softlab Core
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Administrators and users of Softlab Core plugin versions < 1.2.11 should be aware of this vulnerability and take necessary actions to update to a patched version. Security teams should prioritize this vulnerability due to its HIGH severity and potential impact on affected systems.
Technical summary
CVE-2026-34895 is a local file inclusion vulnerability in Softlab Core plugin versions < 1.2.11. The vulnerability allows unauthenticated attackers to include local files, potentially leading to code execution, data exposure, or other malicious activities. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a HIGH severity. The weakness associated with this vulnerability is CWE-98.
Defensive priority
HIGH
Recommended defensive actions
- Update Softlab Core plugin to version 1.2.11 or later
- Restrict access to sensitive files and directories
- Implement additional security measures to prevent local file inclusion attacks
- Monitor systems for suspicious activity
- Consider using a Web Application Firewall (WAF) to detect and prevent attacks
- Regularly review and update software dependencies to ensure timely patching of vulnerabilities
Evidence notes
The information provided is based on data from the NVD database and Patchstack. The CVE record and NVD detail pages provide additional information about the vulnerability. However, due to the limited information available, further research may be necessary to fully understand the vulnerability and its potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-34895 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-34895
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-34895 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34895
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.