PT-2026-8032 · Veramark · Verasmart

Gm Sectec Inc

+2

·

Published

2026-02-13

·

Updated

2026-02-14

·

CVE-2026-26335

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Calero VeraSMART versions prior to 2022 R1
Description The application uses static machineKey values configured for the VeraSMART web application and stored in 'C:Program Files (x86)VeramarkVeraSMARTWebRootweb.config'. An attacker obtaining these keys can create a valid ASP.NET ViewState payload, bypassing integrity validation. This leads to server-side deserialization and remote code execution within the IIS application context.
Recommendations Update to version 2022 R1 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-26335

Affected Products

Verasmart