CVE-2026-26928 Details
Description
SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dynamic library. JAR files are correctly verified based on a list of trusted file hashes, and if a file was not on that list, it was checked to see if it had been digitally signed by the vendor. The application doesn't verify hash or vendor's digital signature of uploaded DLL, SO, JNILIB or DYLIB file. The attacker can provide malicious file which will be saved in users /temp folder and executed by the application. This issue was fixed in version 1.1.0.
A vulnerability exists in SzafirHost, a component of the Szafir SDK Web application, all versions prior to 1.1.0. The issue arises because SzafirHost fails to properly verify the integrity of uploaded dynamic link library files, such as DLL, SO, JNILIB, or DYLIB. While JAR files are validated against a list of trusted hashes or checked for a digital signature from the vendor, this same level of scrutiny is not applied to the aforementioned file types. As a result, an attacker can upload a malicious file that is saved in the user's temporary folder and executed by the application.
Users can update to SzafirHost version 1.1.0 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 2, 2026CISA-ADP
Assessed Apr 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/04/CVE-2026-26927 | [email protected] | AdvisoryBundleRemedy |
| https://www.elektronicznypodpis.pl/ | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-354 | Improper Validation of Integrity Check Value | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Krajowa Izba Rozliczeniowa SzafirHost | All versions |
CPE
Remediation
| |
| Krajowa Izba Rozliczeniowa Szafir SDK Web | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 2, 2026 | New CVE Received | [email protected] |
Volerion