CVE-2026-40551 Details
Description
mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulating the application binary and authenticate as an arbitrary user. This issue affects mpGabinet version 23.12.19 and below.
A vulnerability exists in BinSoft mpGabinet versions through 23.12.19 that allows client-side authentication to be bypassed. An attacker with access to any application instance connected to the backend server can manipulate the application binary to circumvent the login verification process and authenticate as any user. This issue arises from the application's reliance on client-side authentication, which can be exploited by modifying the application binary to bypass login checks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 28, 2026CISA-ADP
Assessed Apr 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/04/CVE-2026-40550/ | [email protected] | AdvisoryBundleRemedy |
| https://www.mpgabinet.pl/ | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-603 | Use of Client-Side Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| BinSoft mpGabinet | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | New CVE Received | [email protected] |
Volerion