CVE-2026-4760 Details
Description
From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account. * Installations based on Panorama Suite 2022-SP1 (22.50.005) are vulnerable unless update PS-2210-02-4079 (or higher) is installed * Installations based on Panorama Suite 2023 (23.00.004) are vulnerable unless updates PS-2300-03-3078 (or higher) and PS-2300-04-3078 (or higher) and PS-2300-82-3078 (or higher) are installed * Installations based on Panorama Suite 2025 (25.00.016) are vulnerable unless updates PS-2500-02-1078 (or higher) and PS-2500-04-1078 (or higher) are installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are vulnerable unless updates PS-2510-02-1077 (or higher) and PS-2510-04-1077 (or higher) are installed Please refer to security bulletin BS-035, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt .
A vulnerability in Panorama Web HMI allows an attacker to read certain server files if they know the file paths and the files are accessible to the Servin process execution account. This issue affects multiple versions of the Panorama Suite, including 2022-SP1, 2023, 2025, and the December 2025 update.
Users should update to the following versions: - Panorama Suite 2022-SP1: PS-2210-04-4079 (or higher) - Panorama Suite 2023: PS-2300-03-3078 (or higher), PS-2300-04-3078 (or higher), and PS-2300-82-3078 (or higher) - Panorama Suite 2025: PS-2500-02-1078 (or higher) and PS-2500-04-1078 (or higher) - Panorama Suite 2025 (updated Dec 2025): PS-2510-02-1077 (or higher) and PS-2510-04-1077 (or higher)
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.codra.net/api/csirt/download?resourceId=1467&fileType=FichierPDF | CODRA |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-552 | Files or Directories Accessible to External Parties | CODRA |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CODRA |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | CVE Modified | CODRA |
| Mar 25, 2026 | New CVE Received | CODRA |