PT-2026-7950 · Gfi · Gfi Archiver

Published

2026-02-12

·

Updated

2026-02-21

·

CVE-2026-2039

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GFI Archiver (affected versions not specified)
Description A flaw exists in the configuration of the MArc.Store.Remoting.exe process, listening on port 8018, due to a lack of authorization before granting access to functionality. This allows remote attackers to bypass authentication on affected systems. Exploitation of this issue, potentially in combination with other flaws, could lead to code execution with SYSTEM privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2039
ZDI-26-077

Affected Products

Gfi Archiver