CVE-2026-42251 Details
Description
Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a legitimate update. This issue affects KS-SOMED with modules: KSPLUPDFTP.exe up to 30.00.00.056 and ANEKSKLIENT.EXE up to 29.00.02.026 Beside removing the hard-coded credentials from the code and changing the update process, access granted by previously exposed credentials was limited to read-only.
A vulnerability in KAMSOFT KS-SOMED exists due to hard-coded credentials that grant unauthorized access to an FTP server hosting the application's update packages. This issue affects KS-SOMED modules 'KSPLUPDFTP.exe' versions prior to 30.00.00.056 and 'ANEKSKLIENT.EXE' versions prior to 29.00.02.026. With the hard-coded credentials, an attacker could upload a malicious update file that might be distributed and installed on client machines as a legitimate update.
Users are advised to update to versions of 'KSPLUPDFTP.exe' through 30.00.00.056 and 'ANEKSKLIENT.EXE' through 29.00.02.026 that do not contain hard-coded credentials. Additionally, the update process should be revised to eliminate the use of such credentials.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 1, 2026CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/06/CVE-2026-1958 | [email protected] | AdvisoryBroken Link |
| https://kamsoft.pl/ks-somed/ | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| KAMSOFT KS-SOMED | <= 30.00.00.056 <= 29.00.02.026 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | New CVE Received | [email protected] |
Volerion