PT-2026-35720 · Mpgabinet · Mpgabinet

Kamil Szczurowski

+1

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-40550

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions mpGabinet versions prior to 23.12.20
Description Privilege Escalation occurs due to excessive database privileges assigned to the application user. An attacker with access to a running application instance connected to the backend server can extract database credentials from the application's memory by inspecting the running process. These exposed credentials provide administrative access to the database, allowing actions that exceed the privileges required for normal application functionality and those permitted through the application interface.
Recommendations Update to a version later than 23.12.19.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40550

Affected Products

Mpgabinet