CVE-2026-4027 Details
Description
A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized access to attachment files due to insufficient access control.
A vulnerability in FlexNet Manager Suite versions 2025 R1 and R2 allows unauthorized users to access attachment files due to inadequate access control. The issue arises because the application fails to properly validate user permissions before granting access to file attachments, potentially leading to the unintended exposure of sensitive information.
FlexNet Manager Suite 2026 R1 will include the necessary fix for on-premises customers. Cloud customers will receive the update automatically as part of the Flexera One ITAM May 2026 release.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.flexera.com/s/feed/0D5PL00000ssjNi0AI | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |