CVE-2026-0392 Details
Description
eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrity-protected. On each launch the application fetches an update descriptor (XML) over TLS but accepts any TLS certificate (a permissive TrustManager and a HostnameVerifier that always returns true), does not verify any digital signature on the update descriptor, and does not verify the Authenticode signature or a checksum of the downloaded installer before running it. A man-in-the-middle attacker able to redirect www.eparaksts.lv can serve a crafted update descriptor pointing to an attacker-controlled executable, which the client downloads and executes, resulting in arbitrary code execution on the victim host.
A vulnerability in eParakstītājs 3.0 for Windows, in versions prior to 1.10.0, allows for arbitrary code execution due to insecure update mechanisms. The application retrieves update descriptors over TLS but accepts any TLS certificate, lacking proper authentication and integrity checks. It fails to verify digital signatures on update descriptors and does not check the Authenticode signature or a checksum of downloaded installers before execution. This flaw enables a man-in-the-middle attacker to serve a malicious update descriptor that points to an attacker-controlled executable, which is then downloaded and executed on the victim's host.
Users are advised to update to eParakstītājs version 1.10.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 3, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cvd.cert.lv/inbox/view/vuln-all-1689187061 | ENISA | Permission Required |
| https://offseq.com/en/research/eparakstitajs-cve-2026-0392/ | ENISA | |
| https://www.eparaksts.lv/lv/par_mums/Jaunumi/Jauna_eParakstitajs_30_versija_1100 | ENISA | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | ENISA |
| CWE-347 | Improper Verification of Cryptographic Signature | ENISA |
| CWE-494 | Download of Code Without Integrity Check | ENISA |
Affected Products
| Product | Versions |
|---|---|
| eParakstītājs | < 1.10.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | ENISA |
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | ENISA |
Volerion