Description
A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be initiated remotely. The vendor was contacted early about this disclosure.
Published: 2026-08-09
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the DefaultFunction of 3CORESec Trapdoor up to version 1.2.2. It causes a weakness in access control that allows attackers to gain unauthorized operation of the function. This flaw can be triggered remotely, giving an attacker the ability to perform actions normally restricted to privileged users. The impact is a potential compromise of confidentiality, integrity, or availability of the system depending on the function’s role within the application.

Affected Systems

Affected systems include 3CORESec Trapdoor versions up to and including 1.2.2. Users running any installation of this software that has not applied the vendor’s fix or updated to a newer patch level may be vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity. No EPSS score is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Because the attack can be initiated remotely and the breadth of affected versions is limited, the likelihood of exploitation is moderate, but systems should prioritize remediation to avoid potentially disruptive unauthorized access.

Generated by OpenCVE AI on August 9, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and deploy the latest 3CORESec Trapdoor update that addresses the DefaultFunction access control flaw.
  • If an update is not yet available, restrict the DefaultFunction to authenticated, authorized users only and disable or remove the function for public or unauthenticated requests.
  • Continuously monitor authentication and access logs for signs of unauthorized attempts to invoke DefaultFunction and investigate any anomalies promptly.

Generated by OpenCVE AI on August 9, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 09 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be initiated remotely. The vendor was contacted early about this disclosure.
Title 3CORESec Trapdoor DefaultFunction access control
First Time appeared 3coresec
3coresec trapdoor
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:3coresec:trapdoor:*:*:*:*:*:*:*:*
Vendors & Products 3coresec
3coresec trapdoor
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

3coresec Trapdoor
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-09T15:45:06.836Z

Reserved: 2026-08-08T18:51:35.024Z

Link: CVE-2026-19358

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T17:30:03Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control