PT-2026-44098 · Gladinet · Triofox Cloud Server Agent

Published

2026-05-27

·

Updated

2026-05-28

·

CVE-2026-8364

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gladinet Triofox Cloud Server Agent (affected versions not specified)
Description Improper handling of remote HTTP messages in the GladServerAgentService.exe, which listens on TCP port 7878, allows unauthenticated attackers to potentially gain unauthorized access or control. The issue occurs when processing requests sent to the following API endpoints: "/resources", "/status", "/sysinfo", "/woshome", "/Settings", "/schedule", and "/DavCache".
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-8364

Affected Products

Triofox Cloud Server Agent