PT-2026-35721 · Binisoft · Mpgabinet

Kamil Szczurowski

+1

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-40551

CVSS v4.0

8.4

High

AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user.
This issue affects mpGabinet version 23.12.19 and below.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-40551

Affected Products

Mpgabinet